Windows Task Host Flaw Gives Local Users SYSTEM

A low-complexity link-following bug in a core Windows background host turns basic local access into full SYSTEM control. The standard response is not enough here: patching closes the flaw, but any attacker who already has a foothold can still use it to take over the machine. CISA added CVE-2025-60710 to its actively exploited catalog and told federal civilian agencies to move within two weeks. Microsoft patched the issue in November 2025 for Windows 11 and Windows Server 2025, and the flaw lets an authorized local attacker with basic permissions elevate to SYSTEM. The risk is not remote break-in. It is privilege escalation from a low-privilege account on systems that often sit inside trusted enterprise and government environments, where SYSTEM access can be enough to disable controls, steal data, or pivot deeper.

Part of the PlainSec briefing for 2026-04-29

Sources