Windows Task Host Vulnerability Exploited by Ransomware Gangs, CISA Warns
CISA has confirmed that ransomware groups are leveraging a critical Windows Task Host vulnerability that was identified as actively exploited in April.
Critical Vulnerability Details
CVE-2025-60710
The flaw, designated as CVE-2025-60710, affects core Windows system components responsible for executing DLL-based processes in the background. The vulnerability, which stems from a link-following weakness, impacts Windows 11 and Windows Server 2025 systems. Exploitation enables local attackers with standard user privileges to escalate to SYSTEM level access, granting full control over unpatched systems.
Microsoft’s Patch and CISA’s Alert
Microsoft addressed the issue in a November 2025 update, but CISA added the flaw to its Known Exploited Vulnerabilities Catalog on April 13, urging federal agencies to implement protections within two weeks. Recent updates to the catalog indicate that ransomware operators are now exploiting the vulnerability. The agency has not disclosed specific attack details, and Microsoft has not yet provided an official statement.
CISA’s Recommendations
CISA emphasized the risk posed by such vulnerabilities, advising organizations to follow vendor mitigation guidelines, adhere to BOD 22-01 cloud security protocols, or discontinue use of affected systems if patches are unavailable.
Previous Vulnerabilities and Trends
This follows earlier warnings from CISA about ransomware groups exploiting a Microsoft SharePoint remote code execution flaw (CVE-2026-45659) since July. Since November 2021, the agency has documented 383 actively exploited vulnerabilities in Microsoft products, with 112 linked to ransomware campaigns.
Security Analysis and Efforts
Analysis of defensive measures reveals that 37% of malicious activities are blocked when attackers possess valid credentials. The Blue Report 2026 evaluates security strategies through 338 million production environment simulations. Additional coverage includes CISA’s alerts on other vulnerabilities, such as the BlueHammer and LegacyHive flaws, as well as ongoing efforts to address zero-day threats in Microsoft products.
