CVE-2026-66804 PoC:Windows Cross Device 虚拟摄像头本地权限提升至 SYSTEM
github.com | 漏洞 | 高危 | CVE-2026-66804 | #public-poc | #privilege-escalation | #windows-security | #windows | #exploit | #dll-hijacking | #com-hijacking | #cwe-284 | #vulnerability | #cve | #poc | #cve-2026-66804 | #dll-planting
摘要
CVE-2026-66804 的 PoC:Windows Cross Device 虚拟摄像头存在缺失路径 DLL 植入缺陷,普通用户可让系统以 LOCAL SERVICE 加载其代码,再提升至 SYSTEM。
为什么值得关注
PoC 展示了标准用户到 SYSTEM 的完整本地提权链,且利用代码已经公开,受影响 Windows 终端应尽快安装微软 2026 年 8 月安全更新。复现会在系统路径植入 DLL 并触发高权限服务,仅应在拥有明确授权的可回滚实验环境中进行。
- 厂商
- Microsoft
- 产品
- Windows Cross Device Service / Cross Device Virtual Camera
- 受影响版本
- Windows 10 22H2 before 10.0.19045.7663; Windows 11 24H2 before 10.0.26100.9168; Windows 11 25H2 before 10.0.26200.9168; Windows 11 26H1 before 10.0.28000.2704
- CVSS
- 7.8
- 发布时间
- 收录时间
Skip to content