CISA: Windows Task Host flaw now exploited by ransomware gangs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently confirmed that ransomware gangs are capitalizing on a significant vulnerability within the Windows Task Host system. This high-severity flaw, tracked as CVE-2025-60710, was first flagged for active exploitation in April and has raised alarms within the cybersecurity community.

Understanding the Vulnerability

Task Host is an essential component of the Windows operating system, responsible for managing DLL-based processes that run in the background. It plays a crucial role in preventing data corruption by ensuring these processes terminate correctly during system shutdowns. The vulnerability in question, which was patched by Microsoft in November 2025, arises from a link-following weakness affecting both Windows 11 and Windows Server 2025 devices.

Once exploited, local attackers with basic user permissions can escalate their privileges to SYSTEM level, granting them full control over unpatched devices. This poses a significant threat, particularly to organizations that have not yet implemented the necessary security updates.

CISA’s Response and Recommendations

While CISA has not disclosed specific details regarding ongoing attacks, it added CVE-2025-60710 to its list of actively exploited vulnerabilities on April 13. The agency provided Federal Civilian Executive Branch (FCEB) agencies with a two-week window to secure their systems against this threat. In a recent update to its Known Exploited Vulnerabilities Catalog (KEV), CISA reiterated that this vulnerability is currently being exploited by ransomware gangs.

Despite inquiries, a Microsoft spokesperson has not yet commented on the situation, leaving many in the industry awaiting further guidance. CISA has issued a stern warning regarding the implications of such vulnerabilities, stating, “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.” The agency urges organizations to apply mitigations as per vendor instructions, adhere to applicable BOD 22-01 guidance for cloud services, or discontinue the use of affected products if mitigations are not feasible.

Broader Context of Cyber Threats

In a related development, CISA recently alerted organizations that ransomware groups have also begun exploiting a Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), which was confirmed to be actively exploited in early July. Since November 2021, CISA has identified a total of 383 actively exploited vulnerabilities across various Microsoft products, with 112 of these also being leveraged in ransomware attacks.

As the landscape of cyber threats continues to evolve, organizations must remain vigilant and proactive in their cybersecurity measures to safeguard against these persistent risks.

Winsage
CISA: Windows Task Host flaw now exploited by ransomware gangs