Executive Summary
In November 2025, Microsoft patched a high-severity privilege escalation vulnerability, CVE-2025-60710, in the Windows Task Host component, which affects Windows 11 and Windows Server 2025 systems. This flaw allows local attackers with basic user permissions to gain SYSTEM-level access by exploiting improper link resolution before file access. Despite the availability of patches, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed in April 2026 that this vulnerability was being actively exploited. By August 2026, CISA reported that ransomware gangs were leveraging CVE-2025-60710 to escalate privileges and deploy ransomware on unpatched systems, posing significant risks to organizations relying on these Windows versions. This incident underscores the critical importance of timely patch management and proactive vulnerability mitigation strategies to prevent exploitation by threat actors.
Why This Matters Now
The active exploitation of CVE-2025-60710 by ransomware gangs highlights the urgent need for organizations to apply available patches and strengthen their security postures to prevent privilege escalation attacks that can lead to severe operational disruptions and data breaches.
Attack Path Analysis
Attackers exploited CVE-2025-60710 to gain initial access to Windows systems. They then escalated privileges to SYSTEM level by exploiting the vulnerability. With elevated privileges, they moved laterally across the network to compromise additional systems. They established command and control channels to maintain persistent access. Sensitive data was exfiltrated from compromised systems. Finally, ransomware was deployed to encrypt data and disrupt operations.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited CVE-2025-60710 to gain initial access to Windows systems.
Related CVEs
CVE-2025-60710
CVSS 7.8Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
Affected Products:
Microsoft Windows 11 Version 24H2 – 10.0.26100.0 up to 10.0.26100.7462
Microsoft Windows 11 Version 25H2 – 10.0.26200.0 up to 10.0.26200.7462
Microsoft Windows Server 2025 – 10.0.26100.0 up to 10.0.26100.7462
Microsoft Windows Server 2025 (Server Core installation) – 10.0.26100.0 up to 10.0.26100.7462
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploitation for Privilege Escalation
Bypass User Account Control
Command and Scripting Interpreter
Valid Accounts
Disable or Modify Tools
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity
Control ID: Pillar 2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face critical ransomware risk from Windows Task Host privilege escalation vulnerability, requiring immediate patching per CISA directive.
Financial Services
Banking systems vulnerable to ransomware attacks exploiting Windows Task Host flaw, threatening encrypted traffic and compliance with PCI standards.
Health Care / Life Sciences
Healthcare infrastructure at high risk from ransomware gangs exploiting Windows privilege escalation, potentially compromising HIPAA-regulated patient data systems.
Information Technology/IT
IT service providers face lateral movement threats through Windows Task Host exploitation, requiring zero trust segmentation and enhanced visibility controls.
Sources
- CISA: Windows Task Host flaw now exploited by ransomware gangshttps://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/Verified
- NVD - CVE-2025-60710https://nvd.nist.gov/vuln/detail/CVE-2025-60710Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-60710Verified
- Microsoft Security Update Guide - CVE-2025-60710http://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it likely limits the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial access may still occur, subsequent attacker actions would likely be constrained, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: Even with elevated privileges, the attacker's ability to access other systems would likely be constrained, reducing the scope of potential damage.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally would likely be constrained, reducing the number of systems that could be compromised.
Control: Multicloud Visibility & Control
Mitigation: Establishing and maintaining command and control channels would likely be more challenging, reducing the attacker's ability to persist within the environment.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration paths would likely be constrained, reducing the volume of data that could be exfiltrated.
The deployment and spread of ransomware would likely be constrained, reducing the overall impact on operations.
Impact at a Glance
Affected Business Functions
- System Administration
- User Access Management
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive system files and user data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit lateral movement and contain potential breaches.
- • Deploy East-West Traffic Security controls to monitor and restrict internal network communications.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Apply patches promptly to address known vulnerabilities like CVE-2025-60710 and reduce the attack surface.



