Microsoft fixed CVE-2026-50343, a Windows 11 local privilege escalation flaw dubbed Dark Elevator that lets a standard user obtain an interactive NT AUTHORITY\SYSTEM shell by coercing InstallService into loading an attacker-controlled DLL inside a SYSTEM svchost.exe process. The issue affects the Windows app installation pipeline and was demonstrated on Windows 11 build 10.0.26200.8457, including Windows 11 25H2, with researchers describing exploitation as deterministic and requiring no administrator rights, UAC approval, reboot, or service-control permissions.
The exploit chains two logic flaws: a user-writable StaticPluginMap registry location that InstallService uses to select COM plugins, and a Windows-shipped CrossDevice COM class whose InprocServer32 DLL path points to a writable location under %PROGRAMDATA%. By abusing COM object loading behavior associated with functions such as CoCreateInstance, an attacker can force privileged code to load a malicious library and execute within a Microsoft-signed SYSTEM service process, enabling persistence, privileged account creation, service installation, tampering with machine-wide settings, access to other users' data, and interference with local security controls.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A local privilege escalation flaw in the Windows Install Service, dubbed "Dark Elevator," was fixed by Microsoft and assigned CVE-2026-50343. The vulnerability allows a normal user to coerce InstallService into loading an attacker-controlled DLL into a SYSTEM svchost.exe process.
A public write-up disclosed exploit details showing how two logic flaws can be chained: a user-writable StaticPluginMap registry location and a writable DLL path for a Windows-shipped CrossDevice COM class. The report said exploitation was deterministic on tested Windows 11 systems and could yield an interactive NT AUTHORITY\SYSTEM shell without admin rights, UAC approval, reboot, or service-control permissions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceblog.calif.io
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.