ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability
ZDI disclosed CVE-2026-66804, a CVSS 7.8 incorrect permission assignment in Windows MIDI Service allowing local privilege escalation.
Zero Day Initiative advisory ZDI-26-617 details an incorrect permission assignment flaw in the Microsoft Windows MIDI Service. An attacker with the ability to run low-privileged code on an affected system can escalate privileges. ZDI rated the issue CVSS 7.8; the advisory provides no evidence of active exploitation.
- Local privilege escalation via incorrect permissions in Windows MIDI Service
- CVSS 3.0 score of 7.8 assigned by ZDI
- Exploitation requires prior low-privileged code execution
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-66804 | Local Privilege Escalation in Microsoft Windows Cross Device Service CVE-2026-66804 is an improper access control vulnerability (CWE-284) in the Windows Cross Device Service, a component shipped with Microsoft Windows 10 and Windows 11. An attacker who already holds a low-privileged account on the local machine can trigger the flaw without any user interaction, abusing the service's misassigned permissions. Successful exploitation elevates the attacker's privileges locally, yielding high-impact confidentiality, integrity, and availability access that typically means full control of the host (CVSS 7.8, AV:L/PR:L/UI:N). Any desktop or laptop running Windows 10 22H2 or Windows 11 24H2, 25H2, or 26H1 is affected. No exploitation has been observed so far - there is no public PoC and the flaw is not in CISA KEV - though EPSS estimates a 5.3% chance of exploitation within 30 days (92nd percentile), and a separate, similarly-classed Windows service LPE (MIDI Service, tracked as ZDI-26-617) was disclosed alongside it. Do: Apply Microsoft's security update for the affected builds via Windows Update, WSUS, or Intune as soon as it is released, prioritizing shared workstations, kiosks, and multi-user hosts where low-privileged local sessions are common. No public workaround or PoC is currently known, so until systems are patched, monitor Microsoft advisories and treat anomalous Cross Device Service activity as suspicious. | 7.8 | 5% |
| mass~hundreds of millions of Windows endpoints (affected builds span the final Windows 10 release and the current mainstream Windows 11 feature updates) |
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66804.
This source does not provide full text. Read it at zerodayinitiative.com.