CVE-2025-60710: Host Process for Windows Tasks Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 7.8)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2025-Nov
- Released
- 2025-11-11
- Last Updated
- 2026-01-02
- EPSS Score
- 0.19% (percentile: 40.9%)
Description
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
FAQ
What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Detection & Weaponization (1 sources)
Maturity: Exploit
- GitHub PoC: 1 repositories
Affected Products (6)
Windows
- Windows Server 2025 (Server Core installation)
- Windows 11 Version 25H2 for ARM64-based Systems
- Windows 11 Version 25H2 for x64-based Systems
- Windows 11 Version 24H2 for ARM64-based Systems
- Windows 11 Version 24H2 for x64-based Systems
- Windows Server 2025
Security Updates (2)
Acknowledgments
@2st___ of Diffract
Thanatos Tian of Diffract
R4nger with Kunlun Lab
Zhiniang Peng with HUST, <a href="https://twitter.com/filip_dragovic">Filip Dragović</a>, <a href="https://x.com/m4x_1997">Aobo Wang</a>, <a href="https://twitter.com/filip_dragovic">Filip Dragović</a>, Joel Land of CISA Vulnerability Response and Coordination
Revision History
- 2025-11-11: Information published.
- 2025-12-09: The following updates have been made:
To comprehensively address CVE-2025-60710, Microsoft has released December 2025 security updates for all supported editions of Windows 11 Version 24H2, Windows 11 Version 25H2, and Windows Server 2025. Microsoft recommends that customers install the updates to be fully protected from the vulnerability. Customers whose systems are configured to receive automatic updates do not need to take any further action.
Added a Workaround for customers running Windows Server 2025, in the event they cannot immediately install the update.
- 2025-12-11: Added an acknowledgement. This is an informational change only.
- 2026-01-02: Added an acknowledgement. This is an informational change only.