Windows Exploitation Techniques: Dangling COM Object Registrations
ResearchWindows COMWindows OSOur summary
Microsoft has fixed CVE-2026-66804, a Windows privilege-escalation flaw involving a dangling registration for the CrossDevice COM object. The issue, an incomplete remediation for CVE-2026-50343, could let a local user place a DLL in a writable ProgramData path and have it loaded by a privileged COM service. Google Project Zero shows how custom COM marshaling and the Shell Create Object Handler could be used to reach SYSTEM-level code execution.
Below is the opening; the full story is at Google Project Zero.
From Google Project Zero
This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows, CVE-2026-66804, that I and 14 others reported. This issue is an incomplete fix for CVE-2026-50343, a bug dubbed “Dark Elevator” CVE-2026-50343/blog.md">by Calif.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.