s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2025-60710

📛 CVE Title

Host Process for Windows Tasks Elevation of Privilege Vulnerability

Description

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

Overview

State
PUBLISHED
Assigner (CNA)
microsoft
CVSS severity
HIGH
CVSS score
CVSS 7.8 / 10 7.8 7.8 / 10
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Effective score
7.8 / 10 HIGH source: CNA overview
MSRC score
7.8 / 10 HIGH MS rating: Important · Elevation of Privilege
CWE(s)
CWE-59
Reserved
2025-09-26
Published
2025-11-11 08:00 UTC
Last updated
2026-01-02 08:00 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/60xxx/CVE-2025-60710.json
Linked Threat
CVE-2025-60710 — Microsoft Windows: Microsoft Windows Link Following Vulnerability

CISA Known Exploited Vulnerabilities CISA KEV

CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.

Vulnerability name
Microsoft Windows Link Following Vulnerability
Vendor / project
Microsoft
Product
Windows
Date added to KEV
2026-04-13
Remediation due
2026-04-27
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Ransomware campaign use
Unknown
CISA notes
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710 ; https://nvd.nist.gov/vuln/detail/CVE-2025-60710
CISA listing
www.cisa.gov/known-exploited-vulnerabilities-catalog

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2025-11-11 18:15:39 UTC
NVD last modified
2026-04-14 14:44:19 UTC
NVD CVSS v3.1
CVSS 7.8 / 10 7.8 7.8 / 10 HIGH source: secure@microsoft.com
NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability subscore
1.8 / 10
Impact subscore
5.9 / 10
EPSS score
0.2290 (probability of exploitation in next 30 days)
EPSS percentile
95.97% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24

NVD / KEV / EPSS data refreshed 2026-05-25 05:02 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2025-93436
Assigner
microsoft
Published
Nov 11, 2025, 5:59:25 PM
Updated
Apr 14, 2026, 3:55:25 AM
EUVD base score (CVSS 3.1)
7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EUVD-reported EPSS
20.8500
Vendors
Microsoft
Products
Windows Server 2025 (10.0.26100.0 <10.0.26100.7462)
Windows 11 Version 25H2 (10.0.26200.0 <10.0.26200.7462)
Windows 11 Version 25H2 (10.0.26200.0 <10.0.26200.7171)
Windows 11 Version 24H2 (10.0.26100.0 <10.0.26100.7462)
Windows Server 2025 (Server Core installation) (10.0.26100.0 <10.0.26100.7462)
Aliases
GHSA-wmgf-g9pc-mvh3

ENISA description: Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

EUVD references (1)

Microsoft Security Response Center MSRC

Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-07-15 03:02 UTC (source: CVRF).

MS severity
Important
Impact
Elevation of Privilege
MS CVSS base score
7.8 / 10 (temporal 6.8)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Exploit assessment
Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Release
2025-Nov
Microsoft remediations / KB articles (5)
  • 5072033 — Vendor Fix / Security Update (fixed build 10.0.26100.7462)
  • https://support.microsoft.com/help/5072033 — None Available / 5072033
  • 5072014 — Vendor Fix / Security Hotpatch Update (fixed build 10.0.26100.7392)
  • https://support.microsoft.com/help/5072014 — None Available / 5072014
  • <p>The following workaround might be helpful in your situation. In all cases, Microsoft strongly recommends that you install the updates for this vulnerability as soon as possible:</p> <p>Customers running Windows Server 2025 who have Desktop Experience installed are affected by this vulnerability. To protect yourself you can disable the following task in Task Scheduler:</p> <p>\Microsoft\Windows\WindowsAI\Recall\PolicyConfiguration</p> <p>You should reenable the task once you have installed the fix.</p> <p><strong>Important</strong>: Do NOT undo the workaround until after you have installed the update.</p> — Workaround
Microsoft FAQ (1)

What privileges could be gained by an attacker who successfully exploited this vulnerability?

An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

Affected products (4)

VendorProductVersionsPlatforms
Microsoft Windows 11 Version 24H2 10.0.26100.0 (affected) ARM64-based Systems, x64-based Systems
Microsoft Windows 11 Version 25H2 10.0.26200.0 (affected)
Microsoft Windows Server 2025 10.0.26100.0 (affected) x64-based Systems
Microsoft Windows Server 2025 (Server Core installation) 10.0.26100.0 (affected) x64-based Systems

Affected products — CPE 2.3 (3) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (10)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (4)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (2)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
cve CVE-2025-60710 no local data 2026-05-14 02:58 UTC
cwe CWE-59 no local data 2026-05-14 02:58 UTC

Flagged vendors

    Remediations (9)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:www.upguard.com

      CVE-2025-60710 is a high-severity local privilege escalation vulnerability in Windows Task Scheduler being actively exploited in the wild.

      2026-05-14 08:48 UTC
    • web:cvefeed.io

      Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

      2026-05-14 08:48 UTC
    • web:nvd.nist.gov

      Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

      2026-05-14 08:48 UTC
    • web:support.microsoft.com

      Branch History Injection Mitigation settings for Windows Server and Azure Stack HCI Security advisories (ADVs) and CVEs provide information provide information about the risk that is posed by these vulnerabilities. They also help you identify the vulnerabilities and identify the default state of mitigations for Windows Server systems.

      2026-05-14 08:48 UTC
    • web:www.bleepingcomputer.com

      CISA warned U.S. government agencies to secure their systems against a Windows Task Host privilege escalation vulnerability that could allow attackers to gain SYSTEM privileges.

      2026-05-14 08:48 UTC
    • web:app.opencve.io

      Apply Microsoft security updates that contain the fix for CVE‑2025‑60710 Verify that the system runs one of the affected Windows 11 or Windows Server 2025 releases before applying the patch If an update is not immediately available, apply the published mitigation scripts to restrict link resolution or adjust host process permissions

      2026-05-14 08:48 UTC
    • web:www.cve.org

      Vulnerability detail for CVE-2025-60710 Notice: Expanded keyword searching of CVE Records (with limitations) is now available in the search box above. Learn more here.

      2026-05-14 08:48 UTC
    • web:www.forbes.com

      As security researchers warn about a dangerous Microsoft Windows update that isn't legitimate, users must pay close attention to what they are actually downloading.

      2026-05-14 08:48 UTC
    • CISA KEV

      Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due date: 2026-04-27 Known ransomware campaign use: Unknown

      2026-05-14 01:13 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2025-60710.json.

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-60710",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-11-07T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2026-04-13",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-60710"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-04-14T03:55:25.244Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-60710"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-04-13T00:00:00.000Z",
                "value": "CVE-2025-60710 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-12-16T17:21:13.750Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.vicarius.io/vsociety/posts/cve-2025-60710-detection-script-eop-vulnerability-in-host-process-for-windows-tasks"
              },
              {
                "url": "https://www.vicarius.io/vsociety/posts/cve-2025-60710-mitigation-script-eop-vulnerability-in-host-process-for-windows-tasks"
              }
            ],
            "title": "CVE Program Container",
            "x_generator": {
              "engine": "ADPogram 0.0.1"
            }
          }
        ],
        "cna": {
          "affected": [
            {
              "platforms": [
                "ARM64-based Systems",
                "x64-based Systems"
              ],
              "product": "Windows 11 Version 24H2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.26100.7462",
                  "status": "affected",
                  "version": "10.0.26100.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Windows 11 Version 25H2",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.26200.7462",
                  "status": "affected",
                  "version": "10.0.26200.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows Server 2025",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.26100.7462",
                  "status": "affected",
                  "version": "10.0.26100.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "platforms": [
                "x64-based Systems"
              ],
              "product": "Windows Server 2025 (Server Core installation)",
              "vendor": "Microsoft",
              "versions": [
                {
                  "lessThan": "10.0.26100.7462",
                  "status": "affected",
                  "version": "10.0.26100.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.0.26100.7462",
                      "versionStartIncluding": "10.0.26100.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*",
                      "versionEndExcluding": "10.0.26200.7462",
                      "versionStartIncluding": "10.0.26200.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*",
                      "versionEndExcluding": "10.0.26100.7462",
                      "versionStartIncluding": "10.0.26100.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "10.0.26100.7462",
                      "versionStartIncluding": "10.0.26100.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "datePublic": "2025-11-11T16:00:00.000Z",
          "descriptions": [
            {
              "lang": "en-US",
              "value": "Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en-US",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59: Improper Link Resolution Before File Access ('Link Following')",
                  "lang": "en-US",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-02-13T20:46:20.562Z",
            "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
            "shortName": "microsoft"
          },
          "references": [
            {
              "name": "Host Process for Windows Tasks Elevation of Privilege Vulnerability",
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710"
            }
          ],
          "title": "Host Process for Windows Tasks Elevation of Privilege Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "assignerShortName": "microsoft",
        "cveId": "CVE-2025-60710",
        "datePublished": "2025-11-11T17:59:25.479Z",
        "dateReserved": "2025-09-26T05:03:24.536Z",
        "dateUpdated": "2026-04-14T03:55:25.244Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }