Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-66804PATCHED
microsoft · windows_10_22h2

Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability

Description

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

Affected Products

VendorProductVersions
microsoftwindows_10_22h210.0.19045.0, 10.0.26100.0, 10.0.26200.0, 10.0.28000.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
googlegoogle cloudcert_advisory90%
lenovolenovo computercert_advisory90%
microsoftwindows 11 version 25h2mitre_affected90%
microsoftmicrosoft windowscert_advisory90%
microsoftwindowscert_advisory90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66804(vendor-advisory, patch)

Related News (5 articles)

Tier C
Google Project Zero6d ago
Windows Exploitation Techniques: Dangling COM Object Registrations
→ No new info (linked only)
Tier B
BSI Advisories46d ago
[NEU] [kritisch] Microsoft Windows Produkte: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR47d ago
Multiples vulnérabilités dans Microsoft Windows (12 août 2026)
→ No new info (linked only)
Tier C
VulDB47d ago
CVE-2026-66804 | Microsoft Windows 10 22H2/11 24H2/11 25H2/11 26H1 access control
→ No new info (linked only)
Tier A
Microsoft MSRC47d ago
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV❌ No
Actively exploited❌ No
Patch available
10.0.19045.766310.0.26100.916810.0.26200.916810.0.28000.2704
CWECWE-284
PublishedAug 11, 2026
Last enriched47d ago
Trending Score26
Source articles5
Independent5
Info Completeness7/14
Missing: title, description, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-85880EXPKEV
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Trending: 79
HIGHCVE-2026-65660
Microsoft SharePoint Server Remote Code Execution Vulnerability
Trending: 72
HIGHCVE-2026-70125
Microsoft Office Outlook Remote Code Execution Vulnerability
Trending: 33
HIGHCVE-2026-100208
Microsoft Office Outlook Remote Code Execution Vulnerability
Trending: 31
CRITICALCVE-2026-70352
Azure AI Language Elevation of Privilege Vulnerability
Trending: 23

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026
Patch Available
Sep 25, 2026