CVE-2025-60710
9.5 CISA KEVMicrosoft · Windows
A privilege escalation vulnerability in the Host Process for Windows Tasks allows an authorized local attacker to gain SYSTEM privileges through improper link resolution before file access.
Executive summary
This critical vulnerability in Microsoft Windows is currently being actively exploited in the wild to facilitate local privilege escalation to SYSTEM level.
Vulnerability
The flaw involves improper link resolution before file access (CWE-59) within the Host Process for Windows Tasks (taskhostw.exe). An authenticated local attacker can manipulate directory junctions and symbolic links to perform arbitrary folder deletions with SYSTEM privileges, effectively escalating their access level.
Business impact
The exploitation of this vulnerability poses a severe risk to organizational security, as it allows a low-privileged local user to gain full SYSTEM control over affected endpoints or servers. Given the CVSS score of 9.5, this flaw represents a critical threat that can lead to complete system compromise, unauthorized data access, and the potential for lateral movement within the network. The confirmed active exploitation significantly increases the likelihood of a successful breach.
Remediation
Immediate Action: Apply the November 2025 security updates provided by Microsoft immediately, as these patches resolve the improper link resolution flaw.
Proactive Monitoring: Monitor system logs for unusual activity involving taskhostw.exe or unexpected modifications to directory junctions and symbolic links by standard user accounts.
Compensating Controls: Ensure that the principle of least privilege is strictly enforced on all Windows systems to limit the ability of unauthorized or standard users to create or manipulate file system links.
Exploitation status
Public Exploit Available: Yes, a public exploit is available.
Analyst recommendation
Due to the confirmed active exploitation and the critical nature of the privilege escalation, organizations must prioritize the deployment of the November 2025 security patches across all affected Windows environments. Delaying this update exposes the infrastructure to significant risk of total system takeover and potential malicious activity. Immediate patching is the only effective way to neutralize this threat.