CVE-2025-60710Active Exploitation(microsoft / windows_11_24h2)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch microsoft windows_11_24h2 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

5.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-59

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_24h2
  • windows_11_25h2
  • windows_server_2025

Threat summary

  • Active exploitation appears in 19 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 26 mentions across 10 observed days

What's happening

  • Active exploitation reported across 19 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 21 signals
  • Disclosure: 4 classified signals
  • Peaked 7d ago at 6 mentions (2026-04-15); latest day: 1
  • 26 total mentions across 10 days

Affected systems

Vendors
Products
windows_11_24h2windows_11_25h2windows_server_2025

Deep dive

Activity timeline26 mentions / 10d
02356Mentions · 2026-04-13: 5Mentions · 2026-04-14: 2Mentions · 2026-04-15: 6Mentions · 2026-04-16: 2Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-08-15: 1Mentions · 2026-08-18: 6Mentions · 2026-08-19: 1Mentions · 2026-08-20: 1PoC Mentioned / Linked · 2026-04-16: 1Active Exploitation · 2026-04-13: 3Active Exploitation · 2026-04-14: 2Active Exploitation · 2026-04-15: 3Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-04-18: 1Active Exploitation · 2026-08-15: 1Active Exploitation · 2026-08-18: 6Active Exploitation · 2026-08-19: 1Active Exploitation · 2026-08-20: 1Patch / Workaround · 2026-04-13: 2Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-15: 2Patch / Workaround · 2026-04-18: 1Patch / Workaround · 2026-08-18: 4Technical Details · 2026-04-13: 4Technical Details · 2026-04-14: 2Technical Details · 2026-04-15: 6Technical Details · 2026-04-16: 2Technical Details · 2026-04-18: 1Technical Details · 2026-08-18: 5Technical Details · 2026-08-19: 104-1304-1404-1504-1604-1704-1808-1508-1808-1908-20
Signal classification4 categories
Active Exploitation
1869.2%
Disclosure
415.4%
Patch
311.5%
General
13.8%
Referenced assets29 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-135
Active Exploitation3Disclosure1Patch1
2026-04-142
Active Exploitation2
2026-04-156
Active Exploitation2Disclosure2Patch2
2026-04-162
Active Exploitation1Disclosure1
2026-04-171
General1
2026-04-181
Active Exploitation1
2026-08-151
Active Exploitation1
2026-08-186
Active Exploitation6
2026-08-191
Active Exploitation1
2026-08-201
Active Exploitation1
Full discourse20 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    6 ثغرات تهدد اغلب الاجهزة والشبكات يتم استغلالها حاليا 🚨 CISA أضافت 6 ثغرات جديدة لقائمة (KEV)Known Exploited Vulnerabilities بعد تأكد الاستغلال الفعلي لها حاليا من قبل المخترقين. الثغرة CVE-2026-21643 (CVSS: 9.1) 🔴 المنتج: FortiClient EMS من Fortinet النوع: SQL Injection التأثير: تنفيذ كود خبيث بدون مصادقة الحالة: استغلال مؤكد منذ 24 مارس 2026 الثغرة CVE-2020-9715 (CVSS: 7.8)🟠 المنتج: Adobe Acrobat Reader النوع: Use-After-Free التأثير: Remote Code Execution ثغرة تستغل من (2020) ولكن تم اكتشافها والاعلان عنها مؤخرا الثغرة CVE-2023-36424 (CVSS: 7.8) 🟠 المنتج: Microsoft Windows Common Log File System Driver النوع: Out-of-Bounds Read التأثير: Privilege Escalation ما فيه تقارير استغلال علنية، بس CISA تؤكد انها تتسغل حاليا . الثغرة CVE-2023-21529 (CVSS: 8.8) 🔴 المنتج: Microsoft Exchange Server النوع: Deserialization of Untrusted Data التأثير: Remote Code Execution المجموعة الصينية Storm-1175 تستغلها لـ Medusa Ransomware. الثغرة CVE-2025-60710 (CVSS: 7.8)🟠 المنتج: Host Process for Windows Tasks النوع: Improper Link Resolution Before File Access التأثير: Local Privilege Escalation الثغرة CVE-2012-1854 (CVSS: 7.8) 📅🟠 المنتج: Microsoft Visual Basic for Applications (VBA) النوع: Insecure Library Loading التأثير: Remote Code Execution ثغرة من 2012! Microsoft عمرها ١٤ سنه ولاتزال تستغل

    Post summary

    The post outlines six CVEs that CISA has confirmed are actively exploited, providing technical details but no PoC, exploit code, patches, or debunking claims.

    16020152.6K
    49.2K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    10件の脆弱性でランサムウェアによる悪用が確認された。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性が更新。対象は以下。 - CVE-2025-60710 (Windows) - CVE-2020-29574 (CyberoamOS) - CVE-2020-0618 (SQL Server) - CVE-2021-4034 (polkit) - CVE-2016-0189 (IE) - CVE-2022-21882 (Windows) - CVE-2019-5591 (FortiOS) - CVE-2019-0803 (Windows) - CVE-2018-0802 (Office) - CVE-2020-0968 (IE)

    Post summary

    CISA reports that ransomware is actively exploiting ten listed CVEs in real-world attacks.

    01121102.7K
    7.8K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2025-60710 to gain SYSTEM privileges on Windows hosts, then pivoting laterally across networks. The privilege escalation involves improper link resolution in Windows Task Host, enabling low-complexity local attacks. Runtime segmentation helps contain post-compromise lateral movement. #ZeroTrust 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/windows-task-host-privilege-escalation-vulnerability-2025

    Post summary

    The text reports that attackers are actively exploiting CVE-2025-60710 via low‑complexity privilege escalation on Windows hosts, enabling lateral movement, with a detailed breakdown link provided.

    50040310
    1.9K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/13追加) 🛡️No.1561 CVE-2012-1854 Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability ✅概要 ・深刻度:重要 7.8 (CVSS Base) / CISA-ADP ・種別:信頼できない検索パス (CWE-426) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft Visual Basic for Applications (VBA) において、DLL検索パスの処理に不備が存在。事前認証されていない攻撃者により、細工されたDLLを特定ディレクトリに配置されることで、正規ライブラリにかわって読み込まされる恐れがある。結果、ユーザーが対象ファイルを開くことで、任意コードが実行される可能性がある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・攻撃者がDLLを配置できる環境であること ・ユーザーが細工されたファイルを開くこと ・VBAが有効な環境 ________________________________________ ✅悪用時影響 ・任意コード実行(ユーザー権限) ・情報漏えいおよび改ざん ・システム可用性への影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2012-1854 https://learn.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-046   🛡️No.1562 CVE-2025-60710 Microsoft Windows Link Following Vulnerability ✅概要 ・深刻度:重要 7.8 (CVSS Base) / Microsoft Corporation ・種別:リンク解釈の問題 (CWE-59) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft Windows において、リンク解決処理に不備が存在。認証済みの攻撃者により、細工されたリンクを介して、本来アクセスできないリソースへアクセスされ、ローカル環境で権限昇格される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・ローカルアクセスが可能であること ・低権限ユーザーであること ・ユーザー操作不要 ________________________________________ ✅悪用時影響 ・権限昇格 ・機密情報の取得および改ざん ・システムへの影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-60710 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710   🛡️No.1563 CVE-2023-21529 Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability ✅概要 ・深刻度:8.8 High (CVSS Base) / NVD ・種別:信頼できないデータのデシリアライゼーション (CWE-502) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft Exchange Serverにおいて、信頼できないデータのデシリアライズ処理に起因する脆弱性が存在。認証済みの攻撃者により、細工されたデータをサーバー上で処理されることで、コード実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・認証済みユーザ権限が必要 ・Exchange Serverへのネットワークアクセス ________________________________________ ✅悪用時影響 ・任意コード実行 ・情報漏えい、改ざん、サービス影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-21529 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21529   🛡️No.1564 CVE-2023-36424 Microsoft Windows Out-of-Bounds Read Vulnerability ✅概要 ・深刻度:7.8 High (CVSS Base) / NVD ・種別:境界外読み取り (CWE-125) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Microsoft Windowsにおいて、境界外読み取りに起因する脆弱性が存在。認証済みの攻撃者により、不正なメモリアクセスを引き起こされることで、機密情報を取得される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:高 ________________________________________ ✅攻撃前提条件 ・ローカルでのログオン権限が必要 ________________________________________ ✅悪用時影響 ・機密情報の漏えい ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2023-36424 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36424   🛡️No.1565 CVE-2020-9715 Adobe Acrobat Use-After-Free Vulnerability ✅概要 ・深刻度:7.8 High (CVSS Base) / NVD ・種別:解放後使用 (CWE-416) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Adobe AcrobatおよびReaderにおいて、解放後使用に起因する脆弱性が存在。事前認証されていない攻撃者により、細工されたPDFファイルをユーザーに開かせることで、メモリ破損を引き起こし、任意のコードを実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・ユーザが細工されたPDFファイルを開く必要がある ________________________________________ ✅悪用時影響 ・任意コード実行 ・情報の取得、改ざん、システム影響 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:未確認 ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2020-9715 https://helpx.adobe.com/security/products/acrobat/apsb20-48.html   🛡️No.1566 CVE-2026-21643 Fortinet FortiClientEMS SQL Injection Vulnerability ✅概要 ・深刻度:9.8 Critical (CVSS Base) / NVD ・種別:SQLインジェクション (CWE-89) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Fortinet FortiClientEMSにおいて、SQLコマンドで使用される特殊要素の不適切な無効化に起因する脆弱性が存在。事前認証されていない攻撃者により、細工されたHTTPリクエストを送信されることで、SQLインジェクションを引き起こされる恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ________________________________________ ✅攻撃前提条件 ・対象システムへネットワークアクセス可能 ________________________________________ ✅悪用時影響 ・任意コマンド実行 ・機密情報の漏えい、改ざん、サービス停止 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:あり(セキュリティ企業による報告) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-21643 https://www.fortiguard.com/psirt/FG-IR-26-XXX   🛡️No.1567 CVE-2026-34621 Adobe Acrobat and Reader Prototype Pollution Vulnerability ✅概要 ・深刻度:8.6 High (CVSS Base) / Adobe Systems Incorporated ・種別:オブジェクトプロトタイプ属性の不適切に制御された変更 (プロトタイプの汚染) (CWE-1321) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Adobe AcrobatおよびReaderにおいて、オブジェクトプロトタイプ属性の不適切に制御された変更に起因する脆弱性が存在。ユーザー権限で任意のコードを実行される恐れがある。 ________________________________________ ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ________________________________________ ✅攻撃前提条件 ・被害者が悪意のあるファイルを開く必要がある ・対象端末でAdobe AcrobatまたはReaderが利用されている必要がある ________________________________________ ✅悪用時影響 ・現在のユーザー権限で任意コード実行 ________________________________________ ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:Adobeが悪用を確認 (Adobeヘルプセンター) ________________________________________ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-34621 https://helpx.adobe.com/security/products/acrobat/apsb26-43.html https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA added seven known-exploited vulnerabilities to its catalog, detailing technical aspects and patch references, confirming active exploitation while no PoC or exploit code was shared.

    000635.7K
    43.5K followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    1/4 🚨 24h Cyber Alert – Aug 18 CISA just dropped a new KEV + flagged a Windows flaw as ransomware-used. Ray RCE. Task Host → SYSTEM. WMIC killed. Azure dumps for sale. Cl0p back. This is the one you save. Full breakdown + actions ↓ 2/4 New KEV: CVE-2025-62593 – Ray (AI compute) code injection RCE Added yesterday. Due Aug 20. CISA also updated CVE-2025-60710 (Windows Task Host) → now confirmed ransomware abuse. Microsoft just removed WMIC (the LOLBIN ransomware uses to kill shadows + AV). Sources: CISA + BleepingComputer (Aug 17-18) 3/4 Active right now: • TheHatman selling 3.6M+ Azure employee records (McD, Gap, Vodafone, TCS…) • Cl0p listing GE + Philips (PTC Windchill path) • Pokémon Center hit via third-party logistics • French tax authority – 678k records stolen Credential + supply-chain pressure is elevated. 4/4 Do this today: ✅ Patch Ray + confirm Task Host (CVE-2025-60710) ✅ Hunt Azure for password spray + MFA fatigue ✅ Check PTC Windchill/FlexPLM for webshells ✅ Kill remaining WMIC usage Bookmark this. RT so your team sees it before the next wave. What’s the first thing you’re checking this morning? #CyberSecurity #KEV #Ransomware #CISA

    Post summary

    The alert announces that CVE‑2025‑62593 and CVE‑2025‑60710 are being actively abused in ongoing ransomware attacks, provides a patch recommendation, and details the exploitation context.

    32000275
    12.4K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    CISA added 7 CVEs to the KEV catalog today. All confirmed active exploitation. CVE-2012-1854 — Microsoft VBA insecure library loading CVE-2020-9715 — Adobe Acrobat UAF CVE-2023-21529 — Exchange deserialization CVE-2023-36424 — Windows OOB read CVE-2025-60710 — Windows link following CVE-2026-21643 — Fortinet SQL injection CVE-2026-34621 — Adobe Acrobat prototype pollution A CVE from 2012 is still being actively exploited in 2026. Patch prioritization isn’t optional. Source: https://t.me/VulnerabilityNews/41878 → http://cisa.gov/known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced seven CVEs in the KEV catalog, all confirmed actively exploited in 2026, covering a range of vulnerabilities from UAF to SQL injection.

    11030214
    184 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Active Exploitation

    CISA、Windows Task Hostの脆弱性(CVE-2025-60710)がランサムウェアグループに悪用されていると確認 KEVカタログを更新 https://rocket-boys.co.jp/security-measures-lab/cisa-windows-task-host-vulnerability-cve-2025-60710-ransomware-kev/ #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性

    Post summary

    CISA confirms CVE-2025-60710 is actively being exploited by ransomware groups, with the KEV catalogue updated.

    01020147
    2.4K followersView on X
  • Andre Gironda@AndreGironda
    Patch

    CVE-2025-60710 mitigation script EoP vulnerability in Host Process for Windows Tasks -- https://www.vicarius.io/vsociety/posts/cve-2025-60710-mitigation-script-eop-vulnerability-in-host-process-for-windows-tasks

    Post summary

    A mitigation script for the CVE-2025-60710 EoP vulnerability affecting the Windows Task Host Process is available, providing a workaround to prevent privilege escalation.

    00021276
    3.8K followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性7件をカタログに追加 CISA Adds Seven Known Exploited Vulnerabilities to Catalog #CISA (Apr 13) CVE-2012-1854 Microsoft Visual Basic for Applications のライブラリ読み込みの脆弱性 CVE-2020-9715 Adobe AcrobatのUse-After-Free脆弱性 CVE-2023-21529 Microsoft Exchange Serverにおける信頼できないデータの逆シリアル化の脆弱性 CVE-2023-36424 Microsoft Windows 境界外読み取りの脆弱性 CVE-2025-60710 Microsoft Windows リンク追跡の脆弱性 CVE-2026-21643 FortinetのSQLインジェクション脆弱性 CVE-2026-34621 Adobe AcrobatおよびReaderプロトタイプ汚染の脆弱性 https://www.cisa.gov/news-events/alerts/2026/04/13/cisa-adds-seven-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced that seven CVEs marked as actively exploited are now catalogued, detailing their technical categories but offering no exploitation code or remediation information.

    00030341
    4.9K followersView on X
  • SOCMinute@SOCMinute
    Active Exploitation

    1/ CISA now says ransomware operations are exploiting CVE-2025-60710, a Windows Task Host privilege-escalation flaw. A local attacker with basic user permissions can use it to gain SYSTEM privileges on an unpatched device. Here’s what defenders need to know. 🧵 https://t.co/818JSro5Go

    Post summary

    The tweet confirms that CVE‑2025‑60710, a Windows Task Host privilege‑escalation flaw, is being actively exploited by ransomware operators, enabling local users to elevate to SYSTEM on unpatched systems.

    1001034
    8 followersView on X
  • SOCMinute@SOCMinute
    Active Exploitation

    4/ CISA added CVE-2025-60710 to its Known Exploited Vulnerabilities Catalog in April. It has now updated the entry to indicate known use in ransomware campaigns. No specific ransomware group or attack chain has been publicly identified.

    Post summary

    CISA reports that CVE‑2025‑60710 is being actively exploited in ransomware campaigns, though no specific threat actor is named.

    1000023
    8 followersView on X
  • Leonel Marin@LeonelM41262107
    Active Exploitation

    🔐 𝗔𝗹𝗲𝗿𝘁𝗮: grupos de ransomware ya explotan una falla de Windows (CVE-2025-60710) que permite tomar control total del equipo. Afecta Windows 11 y Server 2025. El parche existe desde nov. 2025. Más info en : 👇📰 https://whatsapp.com/channel/0029VassZ6m7z4kmqDvFZg07/418 #Ciberseguridad #Ransomware #Colombia https://t.co/FQR45SveGR

    Post summary

    Ransomware groups are actively exploiting CVE-2025-60710 to gain full control of Windows 11 and Server 2025 systems, but a patch was released in November 2025.

    00010114
    28 followersView on X
  • Xavier Rivera@XavierRiveraX
    Active Exploitation

    CISA confirmed ransomware gangs are now exploiting a Windows Task Host privilege escalation flaw, CVE-2025-60710, on Windows 11 and Windows Server 2025. A link-following bug lets a local attacker with basic user rights escalate straight to SYSTEM. Microsoft patched it in November 2025, so unpatched machines already have ransomware crews with a working privilege escalation path.

    Post summary

    CISA confirms ransomware groups are actively exploiting the Windows Task Host privilege escalation flaw (CVE-2025-60710) on unpatched Windows 11 and Server 2025, with Microsoft releasing a patch in November 2025.

    0100086
    596 followersView on X
  • Mr.Rabbit@01ra66it
    Active Exploitation

    【Windows Task HostのCVE-2025-60710は“侵入後”に効くKEV案件】 CVE-2025-60710は、Windows Task Hostにあるlink followingの問題で、認証済みの攻撃者がローカル権限昇格できる脆弱性です。すでにCISA KEV入りしており、単なる理論上の欠陥ではありません。 このタイプの怖さは、VPN侵害や資格情報悪用で低権限 foothold を取られた後に、一気に高権限へ進める点にあります。リモートRCEでなくても、実際の被害チェーンではかなり強い位置を占めます。 防御側はパッチ適用確認だけでなく、侵入後に不自然な昇格やタスク周辺の異常がないか、EDRと認証ログを合わせて見たいところです。 #Windows #CVE202560710 #KEV #PrivilegeEscalation #EDR https://nvd.nist.gov/vuln/detail/CVE-2025-60710

    Post summary

    CVE-2025-60710 is a local privilege escalation vulnerability in Windows Task Host, already listed in the CISA KEV indicating active exploitation; patching, monitoring for suspicious elevation, and EDR checks are recommended.

    00001754
    3.5K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Disclosure

    CVE-2023-21529 Microsoft Exchange Serverにおける信頼できないデータの逆シリアル化の脆弱性 CVE-2023-36424 Microsoft Windows 境界外読み取りの脆弱性 CVE-2025-60710 Microsoft Windows リンク追跡の脆弱性 CVE-2026-21643 FortinetのSQLインジェクション脆弱性

    Post summary

    The text provides a concise disclosure of several Microsoft and Fortinet CVEs, listing their identifiers and brief vulnerability types, without revealing PoC, exploit, patch, or active exploitation details.

    10000378
    40 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    CISA alerts U.S. agencies of a Windows Task Host vulnerability (CVE-2025-60710) allowing local privilege escalation to SYSTEM. Patch released in Nov 2025 for Windows 11 & Server 2025. #WindowsUpdate #PrivilegeEscalation #USA https://ift.tt/pVKZOQM

    Post summary

    CISA announces CVE-2025-60710, a Windows Task Host local privilege escalation flaw, with a patch released in Nov 2025 for Windows 11 and Server 2025.

    00010439
    4.0K followersView on X
  • Michael Martino@battista212
    Active Exploitation

    CVE-2026-21643 Fortinet SQL injection and CVE-2025-60710 Microsoft Windows link following are being actively exploited in the wild. These aren't theoretical — attackers are using them right now.

    Post summary

    CVE-2026-21643 and CVE-2025-60710 are currently being exploited in the wild, with attackers actively using the identified SQL injection and other vulnerabilities.

    10000186
    199 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Ransomware gangs are exploiting CVE-2025-60710 to escalate from basic user access to SYSTEM privileges on Windows 11 and Server 2025 systems. TRC analysis shows attackers then pivot laterally across networks before deploying encryption payloads. Runtime segmentation helps limit blast radius during privilege escalation attacks. #Ransomware #ZeroTrust 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/cisa-windows-task-host-flaw-cve-2025-60710-ransomware-exploitation

    Post summary

    The post reports that ransomware groups are actively exploiting CVE-2025-60710 for privilege escalation and lateral movement on Windows systems, with a reference to a detailed analysis.

    0000065
    1.9K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Active Exploitation

    CyberSec Daily ✓ · 🚨 Active Exploitation · August 18, 2026 🎯 CISA confirms Windows Task Host vulnerability is now being used in ransomware attacks CISA has updated its warning for CVE-2025-60710, confirming that ransomware operators are exploiting the Windows vulnerability in real-world attacks. The privilege-escalation flaw affects Windows 11 and Windows Server 2025 and can allow a local attacker with limited permissions to escalate privileges to SYSTEM. Microsoft originally patched the issue in November 2025, but CISA's updated Known Exploited Vulnerabilities entry now explicitly links the flaw to ransomware activity—raising the urgency for organizations that have delayed patching. 🔗 Source: CISA / BleepingComputer #CISA #Microsoft #Windows #Ransomware #CVE202560710 #CyberSecurity #PatchNow

    Post summary

    CISA confirms CVE-2025-60710 is actively exploited by ransomware operators; Microsoft patched the flaw in November 2025, so unpatched systems should apply the patch immediately.

    0000028
    75 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2025-60710: Windows Task Host Link Following Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04cwNcB0

    Post summary

    The provided text only lists the CVE identifier and a link, with no further details on exploitation or remediation.

    00000513
    28 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_11_25h2---
OSmicrosoftwindows_server_2025---

Explore more