CVE-2025-60710 in Windows Task Host: should your company prioritize this before ransomware actors exploit it?
BLUF
CISA has confirmed that ransomware gangs are actively exploiting CVE-2025-60710, a link-following privilege-escalation flaw in Windows Task Host (Windows 11 and Windows Server 2025). An attacker with basic user privileges can elevate to SYSTEM, and the vulnerability is listed in the CISA KEV catalog with the `knownRansomwareCampaignUse` flag. Microsoft released a patch back in November 2025. Priority: deploy the fix across all in-scope Windows 11 and Windows Server 2025 systems, treating CVE-2025-60710 as a class-A critical issue without delay.
Key facts
- Ransomware gangs are actively exploiting CVE-2025-60710 in campaigns — confirmed by CISA, and the vulnerability carries Known Exploited Vulnerability (KEV) status with `knownRansomwareCampaignUse=Known`.
- The flaw is a link-following privilege-escalation in Windows Task Host that lets an attacker with basic user privileges reach SYSTEM level.
- Affects Windows 11 and Windows Server 2025 among others; Microsoft released the relevant patch in November 2025.
- The vulnerability entered KEV in April 2026; U.S. federal agencies (FCEB) were given two weeks to patch.
- Windows Task Host ships with standard installations, so the attack surface is broad across desktop and server environments.
Decision table: area → what we know → what it means → 30/90-day action
| Area | What we know | What it means for B2B/manufacturing | Recommended 30/90-day action |
|---|---|---|---|
| Patch management | Microsoft patch available since Nov 2025 | Unpatched systems (Windows 11, Server 2025) are a real ransomware target | 30d: urgent patch of critical systems; 90d: full patch coverage and backlog audit |
| Privilege escalation | Link-following vector reaches SYSTEM from basic user rights | One compromised user account can give attackers full endpoint control | 30d: limit local privileges, segment; 90d: review privileged accounts, endpoint EDR |
| Ransomware protection | Ransomware gangs use the flaw in campaigns | Risk of data encryption and production downtime | 30d: update, snapshots, restore tests; 90d: ransomware response playbooks |
| NIS2/KSC alignment | Incident prevention is a risk-management requirement | An unpatched flaw is a single point of incident causes and compliance consequences | 30d: add CVE-2025-60710 to the risk register; 90d: continuous patching as part of NIS2/KSC Readiness |
The view of engineer Marcin Białczyk
In production and B2B environments, the problem I most often see is not a lack of awareness that “you must update” — it is a lack of discipline in *classifying* vulnerabilities. CVE-2025-60710 is not another abstract “critical CVSS score”; it is on the KEV list with confirmed exploitation by ransomware gangs. That changes the priority: this is not “let’s do it at the next maintenance window,” it is a deployment that should be treated as the highest-priority task in the coming days.
In practice, two things matter most. First, verifying whether vulnerable versions actually exist in scope — especially on workstations, which are often skipped while servers get patched. Second, making the process realistic: exploitation data from KEV and CISA advisories should automatically raise the priority of fixes, regardless of the regular patching schedule. These are single, well-documented adjustments to risk management — not an expensive rearchitecture.
From an operational standpoint, I would add one more point: the patch alone is not enough if you do not have a fast path to restore data. A ransomware attack rarely ends with a single vulnerability — it is a chain: entry, escalation, lateral movement, encryption. Patching closes the entry point; tested backups and an incident plan give you time and control if the rest of the chain succeeds.
FAQ
Is my system at risk?
Yes, if you run Windows 11 or Windows Server 2025 without the November 2025 patch and with unrestrained user privileges. Confirm actual state by scanning your scope and checking whether CVE-2025-60710 is flagged as exploited in your vulnerability-management tooling.
Is installing the patch enough?
The patch closes the vector described in the CVE, but full protection also requires limiting user privileges, tested backups, and endpoint monitoring (EDR). Patching is a necessary condition, not a guarantee.
How quickly should I react?
With priority. The vulnerability carries *knownRansomwareCampaignUse* status in KEV, which means active exploitation in campaigns. We recommend deploying the fix to critical systems within days, not waiting for a routine maintenance window.
Will CHORS.NET deploy the patch for me?
CHORS.NET helps plan and verify the patching process and prioritization against KEV/NIS2 criteria, but does not take over the day-to-day deployment of patches in a client’s infrastructure — that remains with the company’s IT team. (More in the services section below.)
How CHORS.NET can help
- Explore our services: English: /uslugi/
- Vulnerability management in the context of NIS2/KSC: /nis2-ksc/
- How we work and our AI policy: /polityka-ai/
- How collaboration with us looks: /o-nas/jak-pracuje-chors-net/
Boundaries and assumptions
- CHORS.NET is not a SOC 24/7 and does not guarantee detection of every incident or full elimination of risk.
- CHORS.NET does not certify NIS2/KSC compliance and does not issue standalone legal opinions; for legal interpretation we work with law firms.
- Patch deployment remains with the organization’s IT team; CHORS.NET supports planning and verification.
- Findings and recommendations reflect knowledge as of the publication date (August 2026).
- This material is informational and technical; it is not legal advice.
Author: eng. Marcin Białczyk, Founder & Cybersecurity Operator at CHORS.NET
Updated: 2026-08-18
Sources:
[1] BleepingComputer — CISA: Windows Task Host flaw now exploited by ransomware gangs (2026-08-18)
[2] CISA — Known Exploited Vulnerabilities Catalog (CVE-2025-60710, knownRansomwareCampaignUse=Known)
[3] Microsoft Security Response Center — advisory CVE-2025-60710 (patch November 2025)
