Project Zero's Forshaw details CVE-2026-66804, an incomplete fix for the Dark Elevator bug. A working exploit is public; August 2026 updates fix it.
A Windows local privilege escalation bug, CVE-2026-66804, lets a standard user plant a DLL where a missing COM server is expected and get it loaded by a SYSTEM service. Microsoft fixed it in the August 2026 security updates. On 21 September 2026 Google Project Zero's James Forshaw published a technique write-up, and he says a fully working exploit is attached to the original issue on the Project Zero tracker. Windows 10 22H2 and Windows 11 24H2, 25H2 and 26H1 are listed as affected until patched.
Which CVE is which
Forshaw's post says the bug is CVE-2026-66804 and that it is "an incomplete fix for CVE-2026-50343, a bug dubbed 'Dark Elevator' by Calif." So the original Dark Elevator bug is CVE-2026-50343, patched in July 2026, and CVE-2026-66804 is the follow-on issue that remained after that fix. Forshaw says he and 14 others reported the later bug.
The Microsoft records name different components. MSRC titles CVE-2026-50343 "Microsoft Install Service Elevation of Privilege Vulnerability" (CWE-269, released 14 July 2026). It titles CVE-2026-66804 "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability" (CWE-284, released 11 August 2026).
Microsoft's ratings
Both records carry a CVSS 3.1 base score of 7.8 and a temporal score of 6.8, scored by Microsoft, with the vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Both are rated Important, both carry the exploitability assessment "Exploitation More Likely", and both say a successful attacker could gain SYSTEM privileges. When we checked on 3 October 2026, MSRC still listed Exploited: No and Publicly disclosed: No for both, even though its CVE-2026-66804 record was last revised on 30 September 2026 and the Project Zero post and exploit are public. Neither CVE is in CISA's Known Exploited Vulnerabilities catalog. Treat the "No" flags as Microsoft's label rather than a sign that exploitation is hard.
MSRC lists these fixed builds for CVE-2026-66804, all requiring a restart:
- Windows 10 22H2: 10.0.19045.7663 (KB5120249)
- Windows 11 24H2: 10.0.26100.9168 (KB5121003)
- Windows 11 25H2: 10.0.26200.9168 (KB5121003)
- Windows 11 26H1: 10.0.28000.2704 (KB5121000)
NVD lists the same 22H2 and 26H1 cut-offs but gives 10.0.26100.9106 and 10.0.26200.9106 for 24H2 and 25H2. Use the MSRC figures, which are higher and therefore safe under either reading.
The bug
The root cause is a dangling COM object registration. The CrossDevice COM class, CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}, is registered in the system-wide classes key, so every user and system service can see it. It points to %PROGRAMDATA%\CrossDevice\CrossDevice.Streaming.Source.dll, and that file does not exist. C:\ProgramData lets any user create directories, so anyone can create the path and drop in their own DLL. Instantiating the class then loads that DLL.
The remaining problem is getting a privileged process to instantiate the class. Per Forshaw, the Dark Elevator route, CVE-2026-50343, abused weak registry key permissions to register the class as an installer plugin and had InstallService load it. That InstallService issue was fixed, but the dangling registration was not, so he needed another route.
The technique
Forshaw uses custom COM marshaling. A COM object that implements IMarshal can name any CLSID as its unmarshaling class. When it is sent to a COM server, the runtime unmarshals it automatically before the target method runs, looks up the in-process server for that CLSID, and loads the DLL. Pointing IMarshal at the dangling CrossDevice CLSID therefore loads the attacker's DLL in the receiving process.
Microsoft has a mitigation that blocks this: the EOAC_NO_CUSTOM_MARSHAL flag passed to CoInitializeSecurity, or COMGLB_UNMARSHALING_POLICY_STRONG set through IGlobalOptions::Set. Many privileged services enable it, so Forshaw looked for a SYSTEM service that does not. He found the Shell Create Object Handler (CLSID 135fd325-45b7-4c30-89f8-4386961669f0), a COM service he has exploited before. It is not directly instantiable, but starting the scheduled task \Microsoft\Windows\Shell\CreateObjectTask, which normal users can start, brings it up. He verified it runs in dllhost.exe as NT AUTHORITY\SYSTEM with CustomMarshalAllowed set to True.
The object's ICreateObject interface takes an IUnknown pointer as its second parameter. Passing the fake marshaled object there triggers the unmarshal and loads the planted DLL as SYSTEM. Forshaw adds that the technique is general: it applies to any dangling COM registration, and to buggy custom unmarshalers. His post ends with a PowerShell snippet, using his OleViewDotNet and NtObjectManager modules, that finds dangling registrations on an unpatched system. Each hit needs manual checking to see whether the DLL path is writable.
What defenders should do
- Install the August 2026 or later cumulative update on Windows 10 22H2 and Windows 11 24H2, 25H2 and 26H1, and confirm builds are at or above the fixed versions listed above. MSRC marks the update as requiring a restart.
- Confirm July 2026 updates are also in place, since that is where CVE-2026-50343 was fixed.
- Assume the technique is reproducible. A working exploit is attached to the Project Zero issue, and MSRC rates both bugs "Exploitation More Likely".
- ThreatFrontier's suggestion, not vendor guidance: watch for new DLLs under C:\ProgramData\CrossDevice, for the scheduled task \Microsoft\Windows\Shell\CreateObjectTask being started by a non-administrator, and for dllhost.exe running as SYSTEM loading libraries from ProgramData.
- Audit your own COM registrations for entries that point to files that do not exist, in particular under user-writable paths.
Sources
- Project Zero, "Windows Exploitation Techniques: Dangling COM Object Registrations": https://projectzero.google/2026/09/windows-dangling-com.html
- MSRC record, CVE-2026-66804: https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2026-66804
- MSRC record, CVE-2026-50343: https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2026-50343
- MSRC affected products, CVE-2026-66804: https://api.msrc.microsoft.com/sug/v2.0/en-US/affectedProduct?$filter=cveNumber%20eq%20'CVE-2026-66804'
- NVD, CVE-2026-66804: https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-66804
- NVD, CVE-2026-50343: https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-50343
- CISA Known Exploited Vulnerabilities: https://www.cisa.gov/known-exploited-vulnerabilities-catalog