Description
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: 5.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Vulnerability in Windows Cross Device Service permits a local attacker with an authorized account to elevate privileges, allowing them to gain higher permissions than intended. This improper access control flaw corresponds to the CWE-284 weakness, where authority checks are insufficient and can be bypassed. The impact of successful exploitation is the ability to run code with elevated rights, potentially compromising the entire system security posture.

Affected Systems

Affected systems include Microsoft Windows 10 22H2 and Microsoft Windows 11 versions 24H2, 25H2, and 26H1. These versions run on x64 or arm64 architectures. Any installation of these operating systems is vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a moderate to high severity, and the EPSS score of 5% suggests a low but non-negligible exploitation likelihood. The vulnerability is not currently listed in the CISA KEV catalog. The probable attack vector involves a local, authorized attacker using the Cross Device Service, which can be abused to increase privileges on the host. Successful exploitation requires only local access and does not rely on remote network attack, making it potentially easier for insiders or malicious users with physical access.

Generated by OpenCVE AI on August 24, 2026 at 17:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Microsoft security update for Windows 10 Version 22H2 and Windows 11 Versions 24H2, 25H2, and 26H1.
  • Disable or restrict the Cross Device Service if it is not required for business operations.
  • Enforce strict local permissions and monitor for abnormal service activity to detect potential privilege escalation attempts.

Generated by OpenCVE AI on August 24, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Vendors & Products Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Fri, 14 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918
References
Metrics threat_severity

None

threat_severity

Important


Wed, 12 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Title Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-284
CPEs cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 22h2 Windows 10 22h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:06:19.061Z

Reserved: 2026-07-27T19:02:26.601Z

Link: CVE-2026-66804

cve-icon Vulnrichment

Updated: 2026-08-12T15:47:58.700Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:01.733

Modified: 2026-08-14T18:06:11.420

Link: CVE-2026-66804

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-13T13:30:00Z

Links: CVE-2026-66804 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T17:30:06Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-918

    Server-Side Request Forgery (SSRF)