References https://nvd.nist.gov/vuln/detail/CVE-2025-60710 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60710 https://www.ihonker.com/thread-34088-1-1.html https://www.gm7.org/archives/21431 https://ybdt.me/2025/11/23/Windows%E4%BB%BB%E5%8A%A1%E8%AE%A1%E5%88%92%E6%9D%83%E9%99%90%E6%8F%90%E5%8D%87%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90%EF%BC%88CVE-2025-60710%EF%BC%89/ https://github.com/redpack-kr/CVE-2025-60710 https://www.rapid7.com/db/vulnerabilities/microsoft-windows-cve-2025-60710/ https://www.vicarius.io/vsociety/posts/cve-2025-60710-detection-script-eop-vulnerability-in-host-process-for-windows-tasks https://www.tenable.com/cve/CVE-2025-60710 https://www.bleepingcomputer.com/news/security/cisa-flags-windows-task-host-vulnerability-as-exploited-in-attacks/
Related VulnerabilitiesWindows截图工具NTLM信息泄露漏洞(CVE-2026-33829)Gradio /static//windows/win.ini 文件读取漏洞 (CVE-2026-28414)Windows Shell Link 敏感信息泄露与欺骗漏洞(CVE-2026-25185)PoCCVE-2025-13315: Twonky Server 8.5.2 on Linux and Windows - Log File ExposureWindows PolicyConfiguration 计划任务特权提升漏洞(CVE-2025-60710)Windows 11 RAiLaunchAdminProcess 管理员保护特权提升漏洞(CVE-2025-62522)Vite开发服务器Windows环境下文件泄露漏洞(CVE-2025-41246) VMware Tools for Windows授权不当漏洞Windows NTLMv2-SSP Hash信息泄露漏洞(CVE-2025-50154)(CVE-2025-26513)SAN Host Utilities for Windows 8.0前版本安装程序本地权限提升漏洞(CVE-2025-8088) WinRAR Windows版本路径遍历漏洞可导致任意代码执行PoCCVE-2015-1635: Microsoft Windows 'HTTP.sys' - Remote Code ExecutionPoCCVE-2017-7269: Windows Server 2003 & IIS 6.0 - Remote Code Execution