Ransomware Gangs Exploit High‑Severity Windows Task Host Vulnerability (CVE‑2025‑60710)
What Happened — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE‑2025‑60710, a privilege‑escalation flaw in Windows Task Host, to its Known Exploited Vulnerabilities catalog. The flaw, patched by Microsoft in November 2025, is now being leveraged by ransomware groups to obtain SYSTEM privileges on unpatched Windows 11 and Windows Server 2025 machines.
Why It Matters for Compliance & Audit Readiness
- The scenario maps directly to SOC 2 CC6.1 (Logical Access Controls) – attackers can bypass least‑privilege policies once they obtain a low‑privilege account.
- Continuous evidence of patch‑management and privileged‑access monitoring is essential to demonstrate due diligence during a SOC 2 audit.
- Verisq’s SOC2 Access Controls capability helps you collect immutable proof that patches are applied and privileged actions are logged, satisfying both security and audit requirements.
Who Is Affected — Enterprises across all verticals that run Windows 11 or Windows Server 2025 workloads, including SaaS providers, cloud‑hosted services, and on‑premises data centers.
Recommended Actions
- Deploy Microsoft’s November 2025 patch for CVE‑2025‑60710 immediately on all affected endpoints.
- Verify patch compliance through automated inventory and continuous monitoring tools.
- Enforce strict least‑privilege policies and privileged‑access‑management (PAM) controls; log all elevation‑of‑privilege events for audit.
- Document remediation steps and retain evidence in a centralized compliance repository.
Source: BleepingComputer
Technical Notes — The vulnerability is a link‑following weakness in the Windows Task Host service that allows a local, low‑privilege user to execute arbitrary code as SYSTEM. CVE‑2025‑60710 was publicly disclosed in November 2025 and carries a CVSS v3.1 base score of 9.8 (Critical). No public ransomware payloads have been shared, but CISA confirms active exploitation.
Source: [CISA KEV Catalog]