CVE-2025-60710
📛 CVE Title
Host Process for Windows Tasks Elevation of Privilege Vulnerability
Description
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- microsoft
- CVSS severity
- HIGH
- CVSS score
- 7.8 / 10
- CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C- Effective score
- 7.8 / 10 HIGH source: CNA overview
- MSRC score
- 7.8 / 10 HIGH MS rating: Important · Elevation of Privilege
- CWE(s)
-
CWE-59 - Reserved
- 2025-09-26
- Published
- 2025-11-11 08:00 UTC
- Last updated
- 2026-01-02 08:00 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/60xxx/CVE-2025-60710.json
- Linked Threat
- CVE-2025-60710 — Microsoft Windows: Microsoft Windows Link Following Vulnerability
CISA Known Exploited Vulnerabilities CISA KEV
CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.
- Vulnerability name
- Microsoft Windows Link Following Vulnerability
- Vendor / project
- Microsoft
- Product
- Windows
- Date added to KEV
- 2026-04-13
- Remediation due
- 2026-04-27
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Ransomware campaign use
- Unknown
- CISA notes
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710 ; https://nvd.nist.gov/vuln/detail/CVE-2025-60710
- CISA listing
- www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2025-11-11 18:15:39 UTC
- NVD last modified
- 2026-04-14 14:44:19 UTC
- NVD CVSS v3.1
- 7.8 / 10 HIGH source: secure@microsoft.com
- NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Exploitability subscore
- 1.8 / 10
- Impact subscore
- 5.9 / 10
- EPSS score
- 0.2290 (probability of exploitation in next 30 days)
- EPSS percentile
- 95.97% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24
NVD / KEV / EPSS data refreshed 2026-05-25 05:02 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2025-93436 - Assigner
- microsoft
- Published
- Nov 11, 2025, 5:59:25 PM
- Updated
- Apr 14, 2026, 3:55:25 AM
- EUVD base score (CVSS 3.1)
-
7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - EUVD-reported EPSS
- 20.8500
- Vendors
- Microsoft
- Products
-
Windows Server 2025 (10.0.26100.0 <10.0.26100.7462)Windows 11 Version 25H2 (10.0.26200.0 <10.0.26200.7462)Windows 11 Version 25H2 (10.0.26200.0 <10.0.26200.7171)Windows 11 Version 24H2 (10.0.26100.0 <10.0.26100.7462)Windows Server 2025 (Server Core installation) (10.0.26100.0 <10.0.26100.7462)
- Aliases
-
GHSA-wmgf-g9pc-mvh3
ENISA description: Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
EUVD references (1)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-07-15 03:02 UTC (source: CVRF).
- MS severity
- Important
- Impact
- Elevation of Privilege
- MS CVSS base score
- 7.8 / 10 (temporal 6.8)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - Exploit assessment
- Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
- Release
- 2025-Nov
Microsoft remediations / KB articles (5)
- 5072033 — Vendor Fix / Security Update (fixed build 10.0.26100.7462)
- https://support.microsoft.com/help/5072033 — None Available / 5072033
- 5072014 — Vendor Fix / Security Hotpatch Update (fixed build 10.0.26100.7392)
- https://support.microsoft.com/help/5072014 — None Available / 5072014
- <p>The following workaround might be helpful in your situation. In all cases, Microsoft strongly recommends that you install the updates for this vulnerability as soon as possible:</p> <p>Customers running Windows Server 2025 who have Desktop Experience installed are affected by this vulnerability. To protect yourself you can disable the following task in Task Scheduler:</p> <p>\Microsoft\Windows\WindowsAI\Recall\PolicyConfiguration</p> <p>You should reenable the task once you have installed the fix.</p> <p><strong>Important</strong>: Do NOT undo the workaround until after you have installed the update.</p> — Workaround
Microsoft FAQ (1)
What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Affected products (4)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | Windows 11 Version 24H2 |
10.0.26100.0 (affected)
|
ARM64-based Systems, x64-based Systems |
| Microsoft | Windows 11 Version 25H2 |
10.0.26200.0 (affected)
|
— |
| Microsoft | Windows Server 2025 |
10.0.26100.0 (affected)
|
x64-based Systems |
| Microsoft | Windows Server 2025 (Server Core installation) |
10.0.26100.0 (affected)
|
x64-based Systems |
Affected products — CPE 2.3 (3) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Host Process for Windows Tasks Elevation of Privilege Vulnerability vendor-advisorypatch
Web references (10)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- 5072033 msrc
- None Available msrc
- 5072014 msrc
- MSRC update guide: CVE-2025-60710 msrc
- https://support.microsoft.com/help/5072033 rapid7:support.microsoft.com
- http://cwe.mitre.org/data/definitions/59.html rapid7:cwe.mitre.org
- https://www.cve.org/CVERecord?id=CVE-2025-60710 rapid7:www.cve.org
- https://attackerkb.com/topics/CVE-2025-60710 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-93436 rapid7:euvd.enisa.europa.eu
- https://support.microsoft.com/help/5068861 rapid7:support.microsoft.com
NVD-tagged references (4)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710 secure@microsoft.com Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-60710 134c704f-9b21-4f2e-91b3-4a467353bcc0 US Government Resource
- https://www.vicarius.io/vsociety/posts/cve-2025-60710-detection-script-eop-vulnerability-in-host-process-for-windows-tasks af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://www.vicarius.io/vsociety/posts/cve-2025-60710-mitigation-script-eop-vulnerability-in-host-process-for-windows-tasks af854a3a-2127-422b-91ae-364da2661108 MitigationThird Party Advisory
Indicators (2)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| cve |
CVE-2025-60710
|
no local data | 2026-05-14 02:58 UTC |
| cwe |
CWE-59
|
no local data | 2026-05-14 02:58 UTC |
Remediations (9)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:www.upguard.com
CVE-2025-60710 is a high-severity local privilege escalation vulnerability in Windows Task Scheduler being actively exploited in the wild.
2026-05-14 08:48 UTC -
web:cvefeed.io
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
2026-05-14 08:48 UTC -
web:nvd.nist.gov
Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
2026-05-14 08:48 UTC -
web:support.microsoft.com
Branch History Injection Mitigation settings for Windows Server and Azure Stack HCI Security advisories (ADVs) and CVEs provide information provide information about the risk that is posed by these vulnerabilities. They also help you identify the vulnerabilities and identify the default state of mitigations for Windows Server systems.
2026-05-14 08:48 UTC -
web:www.bleepingcomputer.com
CISA warned U.S. government agencies to secure their systems against a Windows Task Host privilege escalation vulnerability that could allow attackers to gain SYSTEM privileges.
2026-05-14 08:48 UTC -
web:app.opencve.io
Apply Microsoft security updates that contain the fix for CVE‑2025‑60710 Verify that the system runs one of the affected Windows 11 or Windows Server 2025 releases before applying the patch If an update is not immediately available, apply the published mitigation scripts to restrict link resolution or adjust host process permissions
2026-05-14 08:48 UTC -
web:www.cve.org
Vulnerability detail for CVE-2025-60710 Notice: Expanded keyword searching of CVE Records (with limitations) is now available in the search box above. Learn more here.
2026-05-14 08:48 UTC -
web:www.forbes.com
As security researchers warn about a dangerous Microsoft Windows update that isn't legitimate, users must pay close attention to what they are actually downloading.
2026-05-14 08:48 UTC -
CISA KEV
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-04-27 Known ransomware campaign use: Unknown
2026-05-14 01:13 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2025-60710.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-60710",
"options": [
{
"Exploitation": "active"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-11-07T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
},
{
"other": {
"content": {
"dateAdded": "2026-04-13",
"reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-60710"
},
"type": "kev"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-04-14T03:55:25.244Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"government-resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-60710"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-04-13T00:00:00.000Z",
"value": "CVE-2025-60710 added to CISA KEV"
}
],
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2025-12-16T17:21:13.750Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "https://www.vicarius.io/vsociety/posts/cve-2025-60710-detection-script-eop-vulnerability-in-host-process-for-windows-tasks"
},
{
"url": "https://www.vicarius.io/vsociety/posts/cve-2025-60710-mitigation-script-eop-vulnerability-in-host-process-for-windows-tasks"
}
],
"title": "CVE Program Container",
"x_generator": {
"engine": "ADPogram 0.0.1"
}
}
],
"cna": {
"affected": [
{
"platforms": [
"ARM64-based Systems",
"x64-based Systems"
],
"product": "Windows 11 Version 24H2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.26100.7462",
"status": "affected",
"version": "10.0.26100.0",
"versionType": "custom"
}
]
},
{
"product": "Windows 11 Version 25H2",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.26200.7462",
"status": "affected",
"version": "10.0.26200.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2025",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.26100.7462",
"status": "affected",
"version": "10.0.26100.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Windows Server 2025 (Server Core installation)",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "10.0.26100.7462",
"status": "affected",
"version": "10.0.26100.0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"versionEndExcluding": "10.0.26100.7462",
"versionStartIncluding": "10.0.26100.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*",
"versionEndExcluding": "10.0.26200.7462",
"versionStartIncluding": "10.0.26200.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*",
"versionEndExcluding": "10.0.26100.7462",
"versionStartIncluding": "10.0.26100.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"versionEndExcluding": "10.0.26100.7462",
"versionStartIncluding": "10.0.26100.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2025-11-11T16:00:00.000Z",
"descriptions": [
{
"lang": "en-US",
"value": "Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-59",
"description": "CWE-59: Improper Link Resolution Before File Access ('Link Following')",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-02-13T20:46:20.562Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "Host Process for Windows Tasks Elevation of Privilege Vulnerability",
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710"
}
],
"title": "Host Process for Windows Tasks Elevation of Privilege Vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2025-60710",
"datePublished": "2025-11-11T17:59:25.479Z",
"dateReserved": "2025-09-26T05:03:24.536Z",
"dateUpdated": "2026-04-14T03:55:25.244Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}