Skip to content
feed: live
>_0dayNews
microsoft

CISA: Ransomware Gangs Now Exploit Windows Task Host Flaw

CISA confirms ransomware gangs are actively exploiting a high-severity Windows Task Host vulnerability added to KEV in April. Patch your Windows environment now.

CISA: Ransomware Gangs Now Exploit Windows Task Host Flaw
Photo: Alvesgaspar / Wikimedia Commons · CC BY-SA 4.0
fuseMarisol "Fuse" Delgado·Published ·2 min read

CISA has updated its Known Exploited Vulnerabilities catalog to confirm that ransomware gangs are now actively exploiting a high-severity Windows Task Host vulnerability — a flaw first flagged as exploited in April.

BleepingComputer reported the catalog update on August 18. If this flaw was already on your radar from the April KEV addition and you still haven’t patched, the threat model just changed significantly.

What changed

When CISA added this to KEV in April, exploitation was confirmed but ransomware deployment hadn’t been attributed. The August 18 update specifies that ransomware gangs are now among those using it. That distinction matters for prioritization: ransomware operators are systematic and scale quickly. A flaw in their active toolkit gets exercised across thousands of targets in short order.

Who’s exposed

Any Windows environment that hasn’t applied the vendor-supplied patch. CISA’s KEV policy requires a known mitigation to exist before a flaw can be listed — the fix is available. The question is whether you’ve deployed it.

Federal agencies are bound by CISA’s Binding Operational Directive timelines and need to verify compliance immediately. For everyone else, treat this as high urgency regardless of your patch cycle schedule.

What to do now

Find the specific CVE and patch reference. The CVE identifier, CVSS score, affected versions, and patch details are in the CISA KEV catalog entry — search for “Task Host” or follow the direct link in the BleepingComputer reporting. That’s the authoritative source; don’t rely on secondhand descriptions when CISA publishes the specifics directly.

Patch domain-joined Windows systems and servers first. Ransomware operators target enterprise environments where lateral movement and payload impact are highest. Workstations can follow; servers and domain controllers go first.

Review endpoint telemetry for anomalies. Windows Task Host (taskhostw.exe) is a legitimate system process. Unexpected process spawning, unusual network connections, or privilege escalation events originating from Task Host processes warrant immediate investigation before assuming routine activity.

Don’t defer to the next maintenance window. A confirmed ransomware vector means organized threat actors are deploying this now, not soon. A weeks-long patch window is not acceptable for a KEV-listed, ransomware-confirmed flaw.

Bottom line

CISA confirmed ransomware exploitation. The fix exists. Apply it. The CISA KEV catalog has the CVE ID, scope, and deadline — go there for anything more specific than “patch your Windows systems immediately.”

Found this useful? Share it.