Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability Exploit

This module exploits CVE-2026-66804, an improper access control vulnerability in the Microsoft Windows Cross Device Service, to execute a CORE Impact agent with NT AUTHORITY\SYSTEM privileges. Windows registers the Cross Device virtual-camera COM server at PROGRAMDATA\CrossDevice\CrossDevice.Streaming.Source.dll. On affected systems, the machine-wide registration can exist while PROGRAMDATA\CrossDevice is absent and creatable by a standard user. An attacker can create that missing directory and plant the registered COM DLL. Starting the Cross Device virtual camera then causes Windows Camera Frame Server to load the attacker-controlled DLL as NT AUTHORITY\LOCAL SERVICE. The payload DLL elevates from LOCAL SERVICE to SYSTEM and starts a staged CORE Impact agent. The module follows the guarded fresh-VM reproduction flow: Requires an x64 agent running at medium integrity. Validates the exact machine-wide Cross Device COM registration and requires PROGRAMDATA\CrossDevice to be absent. Stages the CORE Impact agent, creates PROGRAMDATA\CrossDevice, and plants the payload DLL. Starts the Cross Device virtual camera through Media Foundation. Waits for the new agent and verifies that it is running as NT AUTHORITY\SYSTEM.
Exploit Platform
Product Name