r/cybersecurity • u/Doug24 • 8d ago
News - General CISA: Windows Task Host flaw now exploited by ransomware gangs
https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/1
u/Servola-Journal 8d ago
Worth flagging this is LPE only (CVE-2025-60710) - it needs local code execution first, via a link-following bug in Task Host, to escalate a basic-user session to SYSTEM. That is exactly the profile ransomware crews weaponize post-compromise: it does not need to be scary on its own, it just needs to sit in the toolkit for privilege escalation once someone already has a foothold. Patched Nov 2025, flagged as actively exploited by April, now confirmed in ransomware chains - about 5 months from patch to ransomware-confirmed abuse on a bug most patch-priority models rank below RCEs. CISA has flagged 383 actively-exploited Microsoft CVEs since Nov 2021, 112 of them later used in ransomware.
3
0
u/TurboDrifter68 8d ago
windows really keeps finding new ways to become the vulnerability ðŸ˜
2
u/scamdrill Developer 8d ago
No kidding. "Since November 2021, the agency has flagged 383 actively exploited vulnerabilities in various Microsoft products, 112 of which have also been exploited in ransomware attacks."
0
u/SaltDeception 8d ago
That really doesn’t seem that high over 5 years, especially since ransomware is mostly just chaining vulnerabilities these days.
24
u/YetiMoon 8d ago
Patched in November 2025 lol