• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-66804: local privilege escalation in Microsoft Windows 10 Version 22H2

An authorized local user can elevate privileges on Windows systems via an access-control flaw in the Cross Device Service (CVE-2026-66804). The bug affects Windows 10 Version 22H2 and several Windows 11 branches: Windows 10 10.0.19045.0 through before 10.0.19045.7663, Windows 11 24H2 10.0.26100.0 through before 10.0.26100.9168, Windows 11 25H2 10.0.26200.0 through before 10.0.26200.9168, and Windows 11 26H1 10.0.28000.0 through before 10.0.28000.2704; an attacker needs local access with an account to exploit it.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
7.8HIGH
EPSS
0.00298
CWE
CWE-284
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so apply the vendor updates immediately; the vulnerability allows privilege elevation by a local authenticated user and fixed builds are published.

What is CVE-2026-66804?

An authorized local user can elevate privileges on Windows systems via an access-control flaw in the Cross Device Service (CVE-2026-66804). The bug affects Windows 10 Version 22H2 and several Windows 11 branches: Windows 10 10.0.19045.0 through before 10.0.19045.7663, Windows 11 24H2 10.0.26100.0 through before 10.0.26100.9168, Windows 11 25H2 10.0.26200.0 through before 10.0.26200.9168, and Windows 11 26H1 10.0.28000.0 through before 10.0.28000.2704; an attacker needs local access with an account to exploit it.

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 22H2 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.766310.0.19045.7663
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.916810.0.26100.9168
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.916810.0.26200.9168
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.270410.0.28000.2704

Is CVE-2026-66804 being exploited?

Public exploit code is available.

How to fix CVE-2026-66804

  1. Install the Microsoft updates that deliver the fixed builds: 10.0.19045.7663 for Windows 10 Version 22H2, 10.0.26100.9168 for Windows 11 24H2, 10.0.26200.9168 for Windows 11 25H2, or 10.0.28000.2704 for Windows 11 26H1.
  2. If you cannot update immediately, restrict local account access and remove unnecessary local administrative privileges.
  3. Monitor endpoint logs for unexpected privilege escalation behavior and review authentication events for anomalous local logins.

Frequently asked questions

Is CVE-2026-66804 being actively exploited?

Public exploit code is available as of 2026-09-29.

Which Windows 10 Version 22H2 versions are affected by CVE-2026-66804?

Windows 10 Version 22H2 builds from 10.0.19045.0 up to but not including 10.0.19045.7663 are affected; update to 10.0.19045.7663 to remediate.

Is there a patch for CVE-2026-66804?

Yes. Microsoft published fixed builds: 10.0.19045.7663 (Windows 10 22H2) and corresponding fixed builds for affected Windows 11 branches.

Does CVE-2026-66804 require authentication?

Yes. Exploitation requires a local account (an authorized user) to trigger privilege elevation on the affected Windows systems.

References