CVE-2025-60710
Microsoft · Published November 11, 2025
7.8
CVSS v3.1
HIGHCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
Affected Products
- Windows 11 24h2 < 10.0.26100.7392
- Windows 11 25h2 < 10.0.26200.7392
- Windows Server 2025 < 10.0.26100.7392
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H