CVE-2026-66804

Summary

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

Affected Software

VendorProductVersion RangeStatus
MicrosoftWindows 10 Version 22H210.0.19045.0 < 10.0.19045.7663affected
MicrosoftWindows 11 Version 24H210.0.26100.0 < 10.0.26100.9168affected
MicrosoftWindows 11 Version 25H210.0.26200.0 < 10.0.26200.9168affected
MicrosoftWindows 11 version 26H110.0.28000.0 < 10.0.28000.2704affected

Weaknesses

  • CWE-284: CWE-284: Improper Access Control

References