Ransomware crews jump on a Windows Task Host bug that hands over full control of the PC
CISA says criminals are now using CVE-2025-60710, a Windows privilege escalation flaw Microsoft patched in November, to seize SYSTEM-level access on unpatched Windows 11 and Server 2025 machines.

Key points
- CISA confirmed on Friday that ransomware gangs are exploiting CVE-2025-60710, a Windows Task Host privilege escalation bug affecting Windows 11 and Windows Server 2025.
- Microsoft patched the flaw in its November 2025 security update; CISA added it to the Known Exploited Vulnerabilities catalog on April 13.
- Successful exploitation lets a local attacker with basic user rights escalate to SYSTEM, the highest privilege level on a Windows machine.
- Since November 2021, CISA has flagged 383 actively exploited Microsoft vulnerabilities; 112 of those have been used in ransomware attacks.
Ransomware crews are now abusing a Windows bug that Microsoft fixed in November, and federal agencies were told back in April to patch it or stop using the product.
The U.S. Cybersecurity and Infrastructure Security Agency updated its Known Exploited Vulnerabilities catalog on Friday to mark CVE-2025-60710 as being used in ransomware attacks. The flaw sits in Task Host, the background service inside Windows that keeps small programs running cleanly and shuts them down properly when the machine powers off.
On its own the bug does not break into a computer from the internet. It is a privilege escalation flaw, meaning an attacker who is already on the machine as an ordinary user can trick Task Host into promoting them to SYSTEM, the top-level account that can read any file, install any program, and disable security tools.
That is exactly the step ransomware operators need after they get a foothold through a phishing email or a stolen password.
Which computers are at risk?
Windows 11 and Windows Server 2025 machines that have not installed the November 2025 security update. Microsoft's advisory for CVE-2025-60710 describes the underlying weakness as a "link following" issue, where the system can be tricked into acting on a file path an attacker controls.
Home users on current Windows 11 will already have the patch if automatic updates are on. Business fleets are the softer target, especially servers and shared workstations where patching is scheduled or delayed.
What can attackers do once they exploit it?
Everything. SYSTEM privileges let the attacker turn off antivirus, create new administrator accounts, move to other machines on the network, and deploy ransomware, the kind of malicious software that scrambles files and demands payment to unlock them.
CISA has not published details of the specific ransomware crews involved, and Microsoft has not yet updated its advisory to confirm in-the-wild exploitation. BleepingComputer first reported the KEV update on Friday.
What should IT teams do this week?
Install the November 2025 Windows updates on every Windows 11 and Windows Server 2025 machine, then check that the patch actually applied. CISA's guidance under Binding Operational Directive 22-01 gives federal civilian agencies a hard deadline; private-sector defenders should treat it the same way.
If a system cannot be patched, CISA's standing advice is blunt: apply the vendor's workarounds or stop using the product.
| Fact | Detail |
|---|---|
| CVE ID | CVE-2025-60710 |
| Affected products | Windows 11, Windows Server 2025 |
| Patch released | November 2025 |
| Added to CISA KEV | April 13, 2025 |
| Flagged as ransomware-linked | Friday's KEV update |
How this fits the wider pattern
This is not an isolated case. A week earlier CISA warned that ransomware crews were exploiting a Microsoft SharePoint remote code execution bug, CVE-2026-45659, after confirming attacks in early July.
Since November 2021, CISA has tagged 383 Microsoft vulnerabilities as actively exploited. Just under a third of those, 112, have been picked up by ransomware groups.
The pattern is boring and consistent. Microsoft ships a fix. Attackers reverse-engineer it, or wait for slow patchers. Ransomware follows. The window between patch and mass exploitation keeps shrinking.



