Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.
← back | CVE Intelligence

CVE-2026-66804 [High]

Curated 2 security research writeups, vulnerability advisories and exploitation analyses for CVE-2026-66804.

Vendor
Microsoft
Product
Windows Cross Device Service / Cross Device Virtual Camera
Affected versions
Windows 10 22H2 before 10.0.19045.7663; Windows 11 24H2 before 10.0.26100.9168; Windows 11 25H2 before 10.0.26200.9168; Windows 11 26H1 before 10.0.28000.2704
CVSS
7.8
Coverage Span
2026-08-13 → 2026-09-21
Reports
2 related reports

Associated Reports & Timeline

2.
github.com | vulnerability | High | | original ↗ | #public-poc | #privilege-escalation | #windows-security | #windows
A PoC for CVE-2026-66804: a missing-path DLL-planting flaw in Windows Cross Device virtual camera lets a standard user get code loaded as LOCAL SERVICE, then escalate to SYSTEM.
Why it matters: The PoC demonstrates a complete local privilege-escalation chain from a standard user to SYSTEM, and exploit code is now public. Affected Windows endpoints should install Microsoft's August 2026 security updates promptly. Reproduction plants a DLL in a system path and triggers a privileged service, so it should only be performed in an explicitly authorized, recoverable lab environment.