Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-66804 PoC: Windows Cross Device virtual camera local privilege escalation to SYSTEM

Summary

A PoC for CVE-2026-66804: a missing-path DLL-planting flaw in Windows Cross Device virtual camera lets a standard user get code loaded as LOCAL SERVICE, then escalate to SYSTEM.

Why it matters

The PoC demonstrates a complete local privilege-escalation chain from a standard user to SYSTEM, and exploit code is now public. Affected Windows endpoints should install Microsoft's August 2026 security updates promptly. Reproduction plants a DLL in a system path and triggers a privileged service, so it should only be performed in an explicitly authorized, recoverable lab environment.
Vendor
Microsoft
Product
Windows Cross Device Service / Cross Device Virtual Camera
Affected versions
Windows 10 22H2 before 10.0.19045.7663; Windows 11 24H2 before 10.0.26100.9168; Windows 11 25H2 before 10.0.26200.9168; Windows 11 26H1 before 10.0.28000.2704
CVSS
7.8
Published
Collected

original ↗

Related coverage

back