CISA: Windows Task Host flaw now exploited by ransomware gangs

A critical Windows vulnerability that was previously patched by Microsoft has been confirmed to be exploited by ransomware gangs, putting millions of devices at risk. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw, tracked as CVE-2025-60710, to its list of actively exploited vulnerabilities after discovering evidence of in-the-wild attacks.

Task Host is a fundamental Windows component that enables DLL-based processes to run in the background, preventing data corruption during shutdown. However, a link following weakness in this system has allowed local attackers with basic user permissions to gain SYSTEM privileges and take complete control of unpatched devices. This vulnerability affects Windows 11 and Windows Server 2025 devices.

Microsoft patched CVE-2025-60710 back in November 2025, but the fix appears to have been ineffective against determined attackers. CISA has not shared any details on ongoing attacks, but it has emphasized the critical nature of this flaw, warning that “this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.” The agency is urging organizations to apply mitigations according to vendor instructions or discontinue use of the affected product if no fixes are available.

This incident highlights the ongoing challenges in keeping up with the evolving threat landscape. Despite Microsoft’s efforts to patch vulnerabilities, attackers continue to find ways to exploit previously addressed flaws. It also underscores the importance of proactive measures such as regular security updates and robust backup procedures. Organizations must remain vigilant and responsive to emerging threats to protect themselves from the ever-present risk of ransomware attacks.

In practical terms, this vulnerability serves as a stark reminder for organizations to prioritize patch management and keep their systems up-to-date. With millions of devices potentially vulnerable, it’s essential to act swiftly to prevent potential breaches.


Source: Bleeping Computer — 2026-08-18