
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are actively exploiting CVE-2025-60710, a high-severity privilege escalation flaw in Windows Task Host — the system component responsible for managing DLL-based background processes during shutdown. The vulnerability allows an attacker who already has a basic user account on a Windows machine to elevate their privileges all the way to SYSTEM level, giving them complete control over the device.
Microsoft patched CVE-2025-60710 in November 2025, and CISA added it to its Known Exploited Vulnerabilities catalog in April 2026 with a two-week remediation deadline for federal agencies. CISA’s latest update confirms ransomware operators are now actively using the flaw in attacks — a common escalation pattern where attackers gain initial access through phishing or stolen credentials, then use a local privilege flaw to lock up the machine and demand payment. CISA warned: “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.” While most organizations are not federal agencies, the warning signals that this flaw is now a live tool in ransomware operators’ standard playbook.
How to check if you’re affected
Affected versions include Windows 11 and Windows Server 2025. The vulnerability was patched in November 2025 via Microsoft’s monthly cumulative security updates, so any system that has applied those updates is protected. To verify:
- Open Settings → Windows Update → Update history and confirm updates from November 2025 were applied.
- Search for CVE-2025-60710 on Microsoft’s Security Update Guide to identify the specific KB number for your Windows version.
- Organizations managing endpoints through WSUS, SCCM, or Intune should verify the November 2025 cumulative update has deployed fleet-wide.
Systems that have not received updates since October 2025 or earlier remain vulnerable and should be treated as a priority.
