CISA: Windows Task Host flaw now exploited by ransomware gangs
Summary
CISA has confirmed that ransomware gangs are actively exploiting a high-severity Windows Task Host vulnerability. This flaw was initially flagged as actively exploited in April.
IFF Assessment
FOE
The active exploitation of a Windows vulnerability by ransomware gangs is a direct threat to defenders.
Severity
9.8
Critical
(AI Estimated)
The vulnerability is described as high-severity and actively exploited by ransomware, suggesting a high attack vector, high impact on confidentiality, integrity, and availability, and high exploitability.
Defender Context
Defenders should prioritize patching the Windows Task Host vulnerability and monitoring for any signs of exploitation. The active use by ransomware gangs indicates a significant risk of widespread infections and data loss.