Windows Exploitation Techniques: Dangling COM Object Registrations

Executive Summary

This research article details how a privilege‑escalation bug (CVE‑2026‑66804) was abused, stemming from an incomplete fix of CVE‑2026‑50343, known as "Dark Elevator." The flaw involves a dangling COM registration for the CrossDevice COM object (CLSID {E9F83CF2‑E0C0‑4CA7‑AF01‑E90C70BEF496}), where the registry entry points to a DLL that no longer exists. Attackers can exploit this to execute code with elevated privileges on Windows systems.


Intelligence Metadata - Source Publisher: Google Project Zero - Published Date: 2026-09-21T07:00:00+00:00 - Category: research

Original Description: This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows, CVE-2026-66804, that I and 14 others reported. This issue is an incomplete fix for CVE-2026-50343, a bug dubbed “Dark Elevator” by Calif. The root cause of the bug was a dangling COM object registration for the CrossDevice COM object with the CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}. A COM registration typically needs two parts: a server executable, which for in-process components is...

"To accomplish great things, we must dream as well as act."

— Anatole France
Source: Google Project Zero