DIRAS TAKE
Urgent: public exploit code exists, so apply the vendor updates immediately; the vulnerability allows privilege elevation by a local authenticated user and fixed builds are published.
What is CVE-2026-66804?
An authorized local user can elevate privileges on Windows systems via an access-control flaw in the Cross Device Service (CVE-2026-66804). The bug affects Windows 10 Version 22H2 and several Windows 11 branches: Windows 10 10.0.19045.0 through before 10.0.19045.7663, Windows 11 24H2 10.0.26100.0 through before 10.0.26100.9168, Windows 11 25H2 10.0.26200.0 through before 10.0.26200.9168, and Windows 11 26H1 10.0.28000.0 through before 10.0.28000.2704; an attacker needs local access with an account to exploit it.
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 22H2 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7663 | 10.0.19045.7663 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9168 | 10.0.26100.9168 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9168 | 10.0.26200.9168 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2704 | 10.0.28000.2704 |
Is CVE-2026-66804 being exploited?
Public exploit code is available.
How to fix CVE-2026-66804
- Install the Microsoft updates that deliver the fixed builds: 10.0.19045.7663 for Windows 10 Version 22H2, 10.0.26100.9168 for Windows 11 24H2, 10.0.26200.9168 for Windows 11 25H2, or 10.0.28000.2704 for Windows 11 26H1.
- If you cannot update immediately, restrict local account access and remove unnecessary local administrative privileges.
- Monitor endpoint logs for unexpected privilege escalation behavior and review authentication events for anomalous local logins.
Frequently asked questions
Is CVE-2026-66804 being actively exploited?
Public exploit code is available as of 2026-09-29.
Which Windows 10 Version 22H2 versions are affected by CVE-2026-66804?
Windows 10 Version 22H2 builds from 10.0.19045.0 up to but not including 10.0.19045.7663 are affected; update to 10.0.19045.7663 to remediate.
Is there a patch for CVE-2026-66804?
Yes. Microsoft published fixed builds: 10.0.19045.7663 (Windows 10 22H2) and corresponding fixed builds for affected Windows 11 branches.
Does CVE-2026-66804 require authentication?
Yes. Exploitation requires a local account (an authorized user) to trigger privilege elevation on the affected Windows systems.
References
- nvd.nist.gov/vuln/detail/CVE-2026-66804
- cve.org/CVERecord?id=CVE-2026-66804
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66804
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026