Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
Is CVE-2025-60710 exploited?
Listed in the CISA KEV catalog on 2026-04-13.
Federal remediation due 2026-04-27.
Past that date by 156 days.
EPSS puts exploitation in the next 30 days at 5%.
Public exploit code: none found in monitored sources.