A nine-month-old patch meets a ransomware crew
CISA has flagged CVE-2025-60710 as used in ransomware attacks. Microsoft fixed it in November 2025.
SeverityHigh
2 minThreat Intelligence
CISA has updated its Known Exploited Vulnerabilities catalogue to record that CVE-2025-60710 is being used by ransomware operators. The flaw is a link-following weakness in Task Host, the Windows component that runs DLL-based background processes, and it affects Windows 11 and Windows Server 2025.
The effect is privilege escalation: a local attacker holding ordinary user permissions reaches SYSTEM and takes the machine.
The dates are the story
Microsoft released a fix in November 2025. CISA added the vulnerability to the catalogue on 13 April 2026, giving federal civilian agencies two weeks to remediate. The ransomware annotation came on 18 August. That is nine months between an available patch and confirmed criminal use.
The catalogue's own arithmetic puts it in proportion. Since November 2021, CISA has listed 383 actively exploited vulnerabilities in Microsoft products, of which 112 have gone on to be used in ransomware attacks — a little under a third.
CISA's standing assessment is that this class of vulnerability is a frequent attack vector and a significant risk to the federal enterprise. The operational reading for everyone else is narrower: a privilege escalation with a patch this old is not a detection problem, it is an inventory problem.
Retold from BleepingComputer. This is a summary in our own words; follow the link for the original reporting.