Project Zero's working CrossDevice exploit turns ordinary Windows code into SYSTEM.
A dangling system-wide COM registration resolves beneath user-creatable ProgramData.
Affects
Microsoft Windows Cross Device Service and its system-wide COM registration on supported Windows 10 and Windows 11 installations.
What it enables
Local privilege escalation to NT AUTHORITY\SYSTEM
Attacker runs code as a standard Windows user.→↓The attacker creates the missing CrossDevice.Streaming.Source.dll beneath the user-creatable ProgramData path referenced by the system-wide COM registration.→↓The attacker starts the user-accessible Microsoft\Windows\Shell\CreateObjectTask and keeps its SYSTEM-hosted COM service active.→↓A custom-marshaled object naming the dangling CrossDevice CLSID is passed to ICreateObject.→↓COM unmarshalling loads the planted DLL into dllhost running as NT AUTHORITY\SYSTEM.
Why this matters
This is more than publication of a patched CVE: public end-to-end code now crosses the standard-user-to-SYSTEM boundary on affected unpatched builds.
Detail and 4 sources
Required access
Ordinary local code execution on an unpatched Windows system
Affected versions
Windows 10 Version 22H2 before build 19045.7663, Windows 11 Version 24H2 before build 26100.9168, Windows 11 Version 25H2 before build 26200.9168, Windows 11 Version 26H1 before build 28000.2704
Proof of concept
Public exploit code
The standard user plants the missing DLL, keeps the user-accessible CreateObjectTask's SYSTEM service active and passes it a custom-marshaled object; COM then loads the DLL into a SYSTEM dllhost process.
Microsoft identifies the fixed build boundaries, and patched systems close this path.
Evidence
Project Zero published the full end-to-end exploitation chain and states that a fully working exploit is attached to its issueMicrosoft’s CVE record identifies a local Cross Device Service privilege elevation and fixed build boundariesIndependent Japanese-language coverage corroborates the demonstrated SYSTEM DLL load
Preconditions
access:local:unprivileged
code running as an unprivileged local user
Patch reality
Pre-fix images still accepted
No
Reaches end-of-life hardware
Yes
The revocation question is not applicable to the disclosed remediation; “unknown” avoids claiming either complete or incomplete revocation.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.