Vulnerability record

CVE-2026-66804

Severity: HighExploitation: No known exploitation

Patch status

Official fix available since

Apply the vendor's update to every affected system. Check the fixed-in versions below where known.

Basis: NVD patch reference

Description

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-66804 scored CVSS 7.8

    Basis: NIST National Vulnerability Database

  2. Patch releasedUpdate

    Patch released for CVE-2026-66804

    An official fix is now available.

    Basis: NVD patch reference

  3. Disclosed

    Windows Exploitation Techniques: Dangling COM Object Registrations

    Basis: Google Project Zero (security research)

Coverage

References