CISA says ransomware gangs are now using a patched Windows flaw to take full control of vulnerable PCs and servers. The issue, CVE-2025-60710, is a high-severity privilege-escalation bug in Windows Task Host that affects Windows 11 and Windows Server 2025; Microsoft patched it in November 2025. It stems from a link-following weakness and can let a local attacker with basic user access gain SYSTEM privileges.
Why it matters: Organizations running unpatched Windows 11 or Windows Server 2025 systems face added risk that a small foothold can be turned into full device takeover during ransomware intrusions. This raises the urgency to verify the November 2025 Microsoft fix is installed and to review endpoint access that could give attackers local user-level entry.
Sergiu Gatlan
2026.08.18
100% relevant
This article establishes a distinct story because it adds a new, material development beyond earlier KEV inclusion: CISA now specifically says CVE-2025-60710 is being exploited by ransomware gangs.
← Back to all stories