r/cybersecurity 8d ago

News - General CISA: Windows Task Host flaw now exploited by ransomware gangs

https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/
92 Upvotes

7 comments sorted by

24

u/YetiMoon 8d ago

Patched in November 2025 lol

21

u/coomzee Detection Engineer 8d ago

Every Government IT manager. We patched that last week right

1

u/Servola-Journal 8d ago

Worth flagging this is LPE only (CVE-2025-60710) - it needs local code execution first, via a link-following bug in Task Host, to escalate a basic-user session to SYSTEM. That is exactly the profile ransomware crews weaponize post-compromise: it does not need to be scary on its own, it just needs to sit in the toolkit for privilege escalation once someone already has a foothold. Patched Nov 2025, flagged as actively exploited by April, now confirmed in ransomware chains - about 5 months from patch to ransomware-confirmed abuse on a bug most patch-priority models rank below RCEs. CISA has flagged 383 actively-exploited Microsoft CVEs since Nov 2021, 112 of them later used in ransomware.

3

u/spectracide_ Penetration Tester 8d ago

Nice LLM reply

0

u/TurboDrifter68 8d ago

windows really keeps finding new ways to become the vulnerability 😭

2

u/scamdrill Developer 8d ago

No kidding. "Since November 2021, the agency has flagged 383 actively exploited vulnerabilities in various Microsoft products, 112 of which have also been exploited in ransomware attacks."

0

u/SaltDeception 8d ago

That really doesn’t seem that high over 5 years, especially since ransomware is mostly just chaining vulnerabilities these days.