Tendvane

← All articles

SecurityAugust 18, 2026

A Windows flaw patched last November is now ransomware's favourite way up

Every so often a security story boils down to one question: did you install the update? This is one of those. On Tuesday, CISA confirmed that ransomware crews are now exploiting CVE-2025-60710, a flaw in a Windows component called Task Host. Microsoft patched it in November 2025.

Task Host is background plumbing nobody thinks about. It runs scheduled jobs that live inside DLL files and makes sure they close down cleanly instead of corrupting data when the PC shuts off. The bug is what's known as a link-following weakness: the component can be fooled into writing to a file it was never meant to touch. What that buys an attacker is promotion. Someone sitting on your PC with an ordinary user account can lift themselves to SYSTEM, the highest level of control Windows has to give. It rates 7.8 out of 10 for severity and affects Windows 11 and Windows Server 2025.

Worth being precise about what this does and doesn't mean. It isn't how attackers get in - it's what they do once they're already there, having arrived through something you downloaded or a password that leaked. CISA first added it to its exploited-vulnerabilities list back in April and gave federal agencies two weeks to patch. What's new this week is that ransomware operators have picked it up. Microsoft's own advisory still doesn't acknowledge exploitation in the wild, and CISA hasn't named which gangs.

The fix has been sitting in Windows Update since last autumn, so most PCs already have it. The ones that don't are usually machines where updates have been quietly failing for months and nobody noticed. Tendvane's health score flags a PC that's fallen behind, and the Windows Update repair wizard is for the other case, where the updates are there but stubbornly refuse to install.

Sources

Download Tendvane