Junglewise Threat Intelligence

CVE-2026-66804: Microsoft Windows Cross Device Service privilege escalation

CVE-2026-66804 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Cross Device Service contains an access control flaw that allows an authenticated local user to escalate privileges on an affected system. An attacker with valid credentials could exploit this vulnerability to gain elevated administrative access, potentially compromising system integrity and enabling further attacks.

Technical details

The vulnerability is an improper access control issue in Microsoft Windows Cross Device Service. The flaw allows an authorized local attacker to escalate privileges on the affected system. This is a local privilege escalation vulnerability requiring prior authentication or local access. An attacker who successfully exploits this vulnerability could gain elevated administrative privileges, enabling complete system compromise. A security update from Microsoft addresses this issue.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats