CISA Confirms Windows Task Host Ransomware Exploitation

CISA says ransomware groups are actively exploiting CVE-2025-60710, a high-severity privilege-escalation flaw in Microsoft Windows Task Host, also known as Host Process for Windows Tasks. The bug was already flagged as actively exploited in April; CISA’s confirmation adds confirmed ransomware use to that record. The flaw lets a local attacker abuse how Windows follows links before opening a file, so the process can be tricked into touching a different target than intended. That can turn a non-admin foothold into elevated rights on the same machine, which is the privilege level ransomware often needs to deploy payloads and spread impact. For Windows endpoints and servers, the exposure is not limited to initial compromise: any limited access that reaches Task Host can become a local escalation path before the ransomware stage begins. CISA’s callout means the assumption that attackers must already have admin rights no longer holds for this flaw.

Part of the PlainSec briefing for 2026-08-19

Editions

CVEs

Sources