Skip to finding
§
High
Privilege — Windows
Confirmed
CVE-2026-66804

Project Zero's working CrossDevice exploit turns ordinary Windows code into SYSTEM.

A dangling system-wide COM registration resolves beneath user-creatable ProgramData.

Affects

Microsoft Windows Cross Device Service and its system-wide COM registration on supported Windows 10 and Windows 11 installations.

What it enables

Local privilege escalation to NT AUTHORITY\SYSTEM

Attacker runs code as a standard Windows user.→↓The attacker creates the missing CrossDevice.Streaming.Source.dll beneath the user-creatable ProgramData path referenced by the system-wide COM registration.→↓The attacker starts the user-accessible Microsoft\Windows\Shell\CreateObjectTask and keeps its SYSTEM-hosted COM service active.→↓A custom-marshaled object naming the dangling CrossDevice CLSID is passed to ICreateObject.→↓COM unmarshalling loads the planted DLL into dllhost running as NT AUTHORITY\SYSTEM.
Why this matters

This is more than publication of a patched CVE: public end-to-end code now crosses the standard-user-to-SYSTEM boundary on affected unpatched builds.

Detail and 4 sources
Required access

Ordinary local code execution on an unpatched Windows system

Affected versions

Windows 10 Version 22H2 before build 19045.7663, Windows 11 Version 24H2 before build 26100.9168, Windows 11 Version 25H2 before build 26200.9168, Windows 11 Version 26H1 before build 28000.2704

Proof of concept

Public exploit code

The standard user plants the missing DLL, keeps the user-accessible CreateObjectTask's SYSTEM service active and passes it a custom-marshaled object; COM then loads the DLL into a SYSTEM dllhost process.

Microsoft identifies the fixed build boundaries, and patched systems close this path.

Evidence
Project Zero published the full end-to-end exploitation chain and states that a fully working exploit is attached to its issueMicrosoft’s CVE record identifies a local Cross Device Service privilege elevation and fixed build boundariesIndependent Japanese-language coverage corroborates the demonstrated SYSTEM DLL load
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 23, 2026