Security

Windows Exploitation Techniques: Dangling COM Object Registrations

A researcher describes a Windows privilege-escalation flaw, CVE-2026-66804, that Microsoft recently fixes; the flaw is an incomplete fix for CVE-2026-50343, known as “Dark Elevator.” The issue stems from a dangling COM object registration for the CrossDevice COM object.

Image: Google Project Zero

Coverage 1 publisher

  1. Google Project Zero

    Windows Exploitation Techniques: Dangling COM Object Registrations

Articles stay on their publishers’ sites; each link opens the original.