CISA: Windows Task Host flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are exploiting a high-severity Windows Task Host vulnerability. The vulnerability, tracked as CVE-2025-60710, allows local attackers with basic user permissions to gain SY…
Intelligence analysis by Llama

CISA has confirmed that ransomware gangs are exploiting a Windows Task Host vulnerability, allowing attackers to gain SYSTEM privileges and take control of unpatched devices. The vulnerability was patched by Microsoft in November 2025, but ransomware gangs have found a way to exploit it.
Imagine you have a special key that can unlock any door in your house. But, if someone finds out about the key, they can use it to get into your house and take whatever they want. That's kind of like what's happening with the Windows Task Host vulnerability. Ransomware gangs are using a special key to get into people's computers and take control of them.
Analysis
Windows Task Host Flaw Exploited by Ransomware Gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are exploiting a high-severity Windows Task Host vulnerability. The vulnerability, tracked as CVE-2025-60710, allows local attackers with basic user permissions to gain SYSTEM privileges and take full control of unpatched devices.
Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown. The vulnerability stems from a link following weakness that affects Windows 11 and Windows Server 2025 devices.
While Microsoft patched the vulnerability in November 2025, ransomware gangs have found a way to exploit it. CISA added CVE-2025-60710 to its list of actively exploited vulnerabilities on April 13 and gave Federal Civilian Executive Branch (FCEB) agencies two weeks to secure their systems.
"We addressed CVE-2025-60710 in our November 2025 security update release and recommend customers apply the update to remain protected," a Microsoft spokesperson told BleepingComputer. "Customers who have already applied the update are protected and do not need to take further action."
CISA has not yet shared any information about attacks targeting CVE-2025-60710, but the agency has warned that this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Ransomware Gangs Exploiting Vulnerability
Ransomware gangs have been exploiting the Windows Task Host vulnerability to gain SYSTEM privileges and take full control of unpatched devices. This is a significant concern because it allows attackers to access sensitive data and disrupt critical systems.
CISA has warned that ransomware gangs have begun exploiting a Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659) after confirming active exploitation in early July. Since November 2021, the agency has flagged 383 actively exploited vulnerabilities in various Microsoft products, 112 of which have also been exploited in ransomware attacks.
Implications of the Vulnerability
The exploitation of the Windows Task Host vulnerability has significant implications for organizations that have not patched their systems. The vulnerability allows attackers to gain SYSTEM privileges and take full control of unpatched devices, which can lead to data breaches and system disruptions.
Organizations must take immediate action to patch their systems and protect themselves from the exploitation of this vulnerability. CISA has warned that this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Key points
- CISA has confirmed that ransomware gangs are exploiting a Windows Task Host vulnerability.
- The vulnerability allows local attackers with basic user permissions to gain SYSTEM privileges and take full control of unpatched devices.
- Microsoft patched the vulnerability in November 2025, but ransomware gangs have found a way to exploit it.
- CISA has warned that this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
If organizations take immediate action to patch their systems, they can protect themselves from the exploitation of this vulnerability. This will help to prevent data breaches and system disruptions, and will ultimately reduce the risk of ransomware attacks.
If organizations do not take immediate action to patch their systems, they will be at risk of being exploited by ransomware gangs. This can lead to data breaches and system disruptions, and can ultimately result in significant financial losses and reputational damage.



