ZeroHour

CVE-2026-66804

mass

Local Privilege Escalation in Microsoft Windows Cross Device Service

CVSS 3.1
7.8 high
EPSS
5%p92
Published
()
Modified
AI analysis

CVE-2026-66804 is an improper access control vulnerability (CWE-284) in the Windows Cross Device Service, a component shipped with Microsoft Windows 10 and Windows 11. An attacker who already holds a low-privileged account on the local machine can trigger the flaw without any user interaction, abusing the service's misassigned permissions. Successful exploitation elevates the attacker's privileges locally, yielding high-impact confidentiality, integrity, and availability access that typically means full control of the host (CVSS 7.8, AV:L/PR:L/UI:N). Any desktop or laptop running Windows 10 22H2 or Windows 11 24H2, 25H2, or 26H1 is affected. No exploitation has been observed so far - there is no public PoC and the flaw is not in CISA KEV - though EPSS estimates a 5.3% chance of exploitation within 30 days (92nd percentile), and a separate, similarly-classed Windows service LPE (MIDI Service, tracked as ZDI-26-617) was disclosed alongside it.

What to do: Apply Microsoft's security update for the affected builds via Windows Update, WSUS, or Intune as soon as it is released, prioritizing shared workstations, kiosks, and multi-user hosts where low-privileged local sessions are common. No public workaround or PoC is currently known, so until systems are patched, monitor Microsoft advisories and treat anomalous Cross Device Service activity as suspicious.

Affected
microsoft Windows 1022H2
microsoft Windows 1124H2, 25H2, 26H1
Estimated exposure
mass~hundreds of millions of Windows endpoints (affected builds span the final Windows 10 release and the current mainstream Windows 11 feature updates) — Windows 10 and Windows 11 together run on well over a billion devices, and the listed builds - the final Windows 10 branch and recent Windows 11 feature updates - include the Cross Device Service per Microsoft's affected-product list, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 22h2, windows 11 24h2, windows 11 25h2, windows 11 26h1
Weakness
CWE-284
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability

ZDI disclosed CVE-2026-66804, a CVSS 7.8 incorrect permission assignment in Windows MIDI Service allowing local privilege escalation.

Zero Day Initiative advisory ZDI-26-617 details an incorrect permission assignment flaw in the Microsoft Windows MIDI Service. An attacker with the ability to run low-privileged code on an affected system can escalate privileges. ZDI rated the issue CVSS 7.8; the advisory provides no evidence of active exploitation.