CVE-2025-60710

HIGH KEV

Host Process for Windows Tasks - Privilege Escalation

Title source: llm

Description

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

Exploits (2)

nomisec WORKING POC 15 stars
by redpack-kr · local
https://github.com/redpack-kr/CVE-2025-60710

Scores

CVSS v3 7.8
EPSS 0.2041
EPSS Percentile 95.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2026-04-13
VulnCheck KEV 2026-04-13
ENISA EUVD EUVD-2025-93436
CWE
CWE-59
Status published
Products (7)
microsoft/windows_11_24h2 < 10.0.26100.7392
microsoft/windows_11_25h2 < 10.0.26200.7092
Microsoft/Windows 11 Version 24H2 10.0.26100.0 - 10.0.26100.7462
Microsoft/Windows 11 Version 25H2 10.0.26200.0 - 10.0.26200.7462
Microsoft/Windows Server 2025 10.0.26100.0 - 10.0.26100.7462
microsoft/windows_server_2025 < 10.0.26100.7392
Microsoft/Windows Server 2025 (Server Core installation) 10.0.26100.0 - 10.0.26100.7462
Published Nov 11, 2025
KEV Added Apr 13, 2026
Tracked Since Feb 18, 2026