Summary
Host Process for Windows Tasks mishandles link resolution before opening files, allowing a low-privileged local user to influence how taskhostw.exe handles a writable path. The exploit uses a WindowsAI Recall scheduled task and a GUID-named directory under CoreAIPlatform.00\UKP to redirect SYSTEM-context file operations to an attacker-controlled target. Successful exploitation yields local privilege escalation to SYSTEM on affected Windows 11 and Windows Server builds.
Why Planned Fix?
4/6Exploitation Details
Gain SYSTEM-level privileges locally
Privilege EscalationAffected Software
| Product | Affected Versions |
|---|---|
| Windows 11 Version 24H2 | 10.0.26100.0 through 10.0.26100.7461 |
| Windows 11 Version 25H2 | 10.0.26200.0 through 10.0.26200.7461 |
| Windows Server 2025 | 10.0.26100.0 through 10.0.26100.7461 |
| Windows Server 2025 (Server Core installation) | 10.0.26100.0 through 10.0.26100.7461 |
Windows is Microsoft’s desktop and server operating system used to run enterprise endpoints and infrastructure.
Affected ComponentHost Process for Windows Tasks scheduled-task handling and link-following file access logic, including the WindowsAI RecallPolicyCheckUpdateTrigger path.
Host Process for Windows Tasks scheduled-task handling and link-following file access logic, including the WindowsAI RecallPolicyCheckUpdateTrigger path.
Affected Endpoints(2)\Microsoft\Windows\WindowsAI\Recall\PolicyConfiguration, C:\Users\%USERNAME%\AppData\Local\CoreAIPlatform.00\UKP\…
Not available
Not available
Install the December 2025 Microsoft security updates for Windows 11 Version 24H2/25H2 and Windows Server 2025. Update to build 10.0.26100.7462 or 10.0.26200.7462, or later, depending on edition.
Install the December 2025 Microsoft security updates for Windows 11 Version 24H2/25H2 and Windows Server 2025. Update to build 10.0.26100.7462 or 10.0.26200.7462, or later, depending on edition.
Probability of exploitation in the next 30 days
Worse than 41% of all CVEs
No known threat actors
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected Software (CPE) (1)
- •cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*
Sources
Priority History
Initial analysis