Junglewise Threat Intelligence

CVE-2025-60710: Microsoft Windows privilege escalation in Host Process for Windows Tasks

CVE-2025-60710 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2026-04-13

Technologies: Microsoft Windows, Microsoft Windows 11 25h2, Microsoft Windows 11 24h2, Microsoft Windows Server 2025. Vendors: Microsoft.

Executive brief

A vulnerability in the Windows Task Scheduler host process allows a user with limited access to gain full administrative control over a computer. This flaw is being actively exploited in the wild, potentially allowing attackers to bypass security restrictions, access sensitive data, or install persistent malware. Organizations should prioritize patching affected Windows 11 and Windows Server 2025 systems immediately.

Technical details

A link following vulnerability (CWE-59) exists in the Host Process for Windows Tasks (taskhostw.exe). The flaw stems from improper link resolution before file access, which a locally authenticated attacker can exploit to redirect file operations to a target of their choosing. By manipulating symbolic links or junctions, an attacker with low privileges can achieve SYSTEM-level execution. This vulnerability has been observed in active exploitation and affects modern versions of Windows 11 and Windows Server 2025.

Affected products

  • Microsoft Windows 11 25H2 up to (excluding) 10.0.26200.7392
  • Microsoft Windows 11 24H2 up to (excluding) 10.0.26100.7392
  • Microsoft Windows Server 2025 up to (excluding) 10.0.26100.7392

Timeline

  • 2025-11-11: disclosed: Initial disclosure by Microsoft
  • 2026-04-13: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2026-04-13: exploited: Confirmed active exploitation in the wild

Related threats