Ransomware crews jump on a Windows Task Host bug that hands over full control of the PC
CISA says criminals are now using CVE-2025-60710, a Windows privilege escalation flaw Microsoft patched in November, to seize SYSTEM-level access on unpatched Windows 11 and Server 2025 machines.

Key points
- CISA confirmed on Friday that ransomware gangs are exploiting CVE-2025-60710, a Windows Task Host privilege escalation bug affecting Windows 11 and Windows Server 2025.
- Microsoft patched the flaw in its November 2025 security update; CISA added it to the Known Exploited Vulnerabilities catalog on April 13.
- Successful exploitation lets a local attacker with basic user rights escalate to SYSTEM, the highest privilege level on a Windows machine.
- Since November 2021, CISA has flagged 383 actively exploited Microsoft vulnerabilities; 112 have been used in ransomware attacks.
Ransomware crews are abusing a Windows bug Microsoft fixed months ago, and federal agencies were already told in April to patch it or walk away from the product.
CISA updated its Known Exploited Vulnerabilities catalog on Friday to mark CVE-2025-60710 as actively used in ransomware attacks. The flaw lives in Task Host, the background Windows service that lets DLL-based processes run cleanly and prevents data corruption by ensuring they shut down properly when the machine powers off.
The bug doesn't break in from the internet on its own. It's a privilege escalation flaw: an attacker already on the machine as an ordinary user can trick Task Host into promoting them to SYSTEM, the top-level account that can read any file, disable security tools, and install software. That's exactly the step ransomware operators need after they've got a foothold through phishing or a stolen password.
Which computers are at risk?
Windows 11 and Windows Server 2025 machines that haven't installed the November 2025 security update. Microsoft's advisory for CVE-2025-60710 describes the weakness as a "link following" issue, where the system can be tricked into acting on a file path the attacker controls.
Home users on current Windows 11 will already have the patch if automatic updates are on. Business fleets are the softer target: servers and shared workstations where patching is scheduled or perpetually delayed.
What can attackers do once they exploit it?
Everything. SYSTEM privileges let the attacker turn off antivirus, create new administrator accounts, move laterally to other machines on the network, and deploy ransomware, malicious software that scrambles files and holds them for payment.
CISA hasn't named the specific ransomware crews involved, and Microsoft hadn't updated its advisory to confirm in-the-wild exploitation when BleepingComputer asked on Friday.
What should IT teams do this week?
Install the November 2025 Windows updates on every affected machine, then verify the patch actually applied. CISA's Binding Operational Directive 22-01 gives federal civilian agencies a hard deadline; private-sector defenders should treat it the same way. If a system can't be patched, CISA's standing advice is to apply vendor workarounds or stop using the product.
| Fact | Detail |
|---|---|
| CVE ID | CVE-2025-60710 |
| Affected products | Windows 11, Windows Server 2025 |
| Patch released | November 2025 |
| Added to CISA KEV | April 13, 2025 |
| Flagged as ransomware-linked | Friday's KEV update |
How this fits the wider pattern
This isn't an isolated case. A week earlier CISA warned that ransomware crews were exploiting a Microsoft SharePoint remote code execution bug, CVE-2026-45659, after confirming attacks in early July. We've tracked this acceleration before: our 6 August piece "The Window Between a New Vulnerability and an Active Attack Is Getting Shorter" found that the real problem isn't a shortage of warnings, it's acting on them before criminals do.
Since November 2021, CISA has tagged 383 Microsoft vulnerabilities as actively exploited; 112 of those have been picked up by ransomware groups.
The pattern is consistent and dull. Microsoft ships a fix. Attackers reverse-engineer the patch, or simply wait for slow patchers. Ransomware follows. The gap between patch release and mass exploitation keeps narrowing, and this case is one more data point in that line.



