Google Project Zero disclosed CVE-2026-66804, a Windows local privilege-escalation flaw caused by a dangling system-wide COM registration for the CrossDevice class. The registration referenced a missing DLL in a user-writable ProgramData location, allowing a local attacker to place a malicious DLL where it could be loaded by a privileged process.
Exploitation uses custom COM marshaling to make a SYSTEM-level Shell Create Object Handler COM server unmarshal the dangling CLSID and load the attacker-controlled DLL, potentially granting SYSTEM-level execution. The vulnerability was an incomplete remediation of CVE-2026-50343 (Dark Elevator); Microsoft has issued a fix, and Project Zero reported that a working exploit was supplied with the original report.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Google Project Zero detailed how custom COM marshaling could make a SYSTEM-level Shell Create Object Handler server load an attacker-controlled DLL through the dangling CrossDevice CLSID. The author stated that a fully working exploit was attached to the original vulnerability report.
Microsoft fixed CVE-2026-66804, a Windows local privilege-escalation vulnerability involving a dangling system-wide CrossDevice COM registration. A local user could plant a DLL in a user-writable ProgramData path and have it loaded by a privileged process.
Microsoft fixed the InstallService abuse path used by CVE-2026-50343, the vulnerability known as Dark Elevator. The remediation did not eliminate a dangling CrossDevice COM registration that could be abused through a different technique.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.