CVE Tools

Windows Exploitation Techniques: Dangling COM Object Registrations

Google Project ZeroBy James Forshaw8 min read

ResearchWindows COMWindows OS

Our summary

Microsoft has fixed CVE-2026-66804, a Windows privilege-escalation flaw involving a dangling registration for the CrossDevice COM object. The issue, an incomplete remediation for CVE-2026-50343, could let a local user place a DLL in a writable ProgramData path and have it loaded by a privileged COM service. Google Project Zero shows how custom COM marshaling and the Shell Create Object Handler could be used to reach SYSTEM-level code execution.

Read at Google Project Zero

Below is the opening; the full story is at Google Project Zero.

From Google Project Zero

This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows, CVE-2026-66804, that I and 14 others reported. This issue is an incomplete fix for CVE-2026-50343, a bug dubbed “Dark Elevator” CVE-2026-50343/blog.md">by Calif.…

Continue at Google Project Zero

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store