Executive brief
Windows Cross Device Service contains an access control flaw that allows an authenticated local user to escalate privileges on an affected system. An attacker with valid credentials could exploit this vulnerability to gain elevated administrative access, potentially compromising system integrity and enabling further attacks.
Technical details
The vulnerability is an improper access control issue in Microsoft Windows Cross Device Service. The flaw allows an authorized local attacker to escalate privileges on the affected system. This is a local privilege escalation vulnerability requiring prior authentication or local access. An attacker who successfully exploits this vulnerability could gain elevated administrative privileges, enabling complete system compromise. A security update from Microsoft addresses this issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-08-11: disclosed