ZeroHour

CVE-2025-60710

KEV ransomwaremass1

Link Following Privilege Escalation in Microsoft Windows Host Process for Tasks

CISA: Microsoft Windows Link Following Vulnerability

CVSS 3.1
7.8 high
EPSS
5%p91
Published
()
KEV added
AI analysis

CVE-2025-60710 is a link-following flaw (CWE-59, improper link resolution before file access) in the Host Process for Windows Tasks on Microsoft Windows. A local attacker with limited (low-privilege) access can trigger the flaw by causing the host process to follow a manipulated link or junction/symlink during file access, redirecting its privileged file operations. Successful exploitation yields elevation of privilege on the local system, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.8). Affected systems are Windows 11 24H2, Windows 11 25H2, and Windows Server 2025. The vulnerability is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13 with known ransomware use, and EPSS estimates a 4.6% chance of exploitation in the next 30 days (91st percentile).

What to do: Apply Microsoft's current security updates for Windows 11 24H2, Windows 11 25H2, and Windows Server 2025 as soon as possible, prioritizing servers and workstations accessible to ransomware operators; the local attack vector means any compromised low-privileged account or endpoint is sufficient. Federal agencies and BOD 22-01-covered organizations must remediate or apply vendor mitigations per the KEV required action within the standard KEV timeline. Inventory systems still running unpatched 24H2/25H2 and Server 2025 builds, and monitor for post-compromise local privilege escalation activity as part of ransomware incident response.

Affected
microsoft Windows 11 24H224H2 (all builds prior to the vendor security update; no specific version range provided in source data)
microsoft Windows 11 25H225H2 (all builds prior to the vendor security update; no specific version range provided in source data)
microsoft Windows Server 20252025 (all builds prior to the vendor security update; no specific version range provided in source data)
Estimated exposure
masshundreds of millions of endpoints (Windows 11 24H2/25H2 workstations plus Windows Server 2025 deployments) — Windows 11 runs on hundreds of millions of devices worldwide with 24H2/25H2 as its current feature updates, and Windows Server 2025 is the current Windows Server release widely deployed in enterprise fleets, so the potentially affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 11 24h2, windows 11 25h2, windows server 2025
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

CISA warns ransomware gangs now exploit critical VMware vCenter syslog RCE CVE-2026-59310, already KEV-listed after APT compromises across 47 countries.

Broadcom patched critical directory traversal flaw CVE-2026-59310 in the vCenter Syslog server on July 29, warning of unauthenticated remote code execution. QUIRSO subsequently found 361 compromised IPs across 47 countries after a suspected APT deployed a reverse SSH tool for persistence and remote access. CISA added the flaw to its KEV catalog with a three-day patch deadline for federal agencies, and over the weekend updated it to flag active abuse by ransomware gangs. Shadowserver tracks over 450 exposed vCenter servers, and CISA has tagged 26 VMware vulnerabilities as exploited in the wild over five years, nine abused by ransomware.