Google Project Zero described the exploitation of CVE-2026-66804, a recently fixed Windows privilege-escalation vulnerability. The cause is a dangling COM registration, a component entry without its server file, for the CrossDevice object.

The registration was available to every user, but its server DLL was missing from C:\ProgramData, where any user can create directories. An attacker can therefore create an arbitrary DLL there and load it when the COM object is instantiated, potentially gaining elevated privileges.

The authors found Shell Create Object Handler, a COM service that runs as SYSTEM and allows custom COM marshaling, a way to pass COM objects between processes. A normal user can start it by using the CreateObjectTask scheduled task.

Claim check:

  • Google Project Zero described the exploitation of CVE-2026-66804, a recently fixed Windows privilege-escalation vulnerability. (confirmed by the publication itself: evidence; «This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows, CVE-2026-66804»)
  • The cause of CVE-2026-66804 is a dangling registration for the CrossDevice COM object. (confirmed by the publication itself: evidence; «The root cause of the bug was a dangling COM object registration for the CrossDevice COM object»)
  • The registration was available to every user, but its server DLL was missing from C:\ProgramData, where any user can create directories. (confirmed by the publication itself: evidence; «This object was registered in the system wide classes key, meaning it was accessible to all users on the system, including system services. However the server executable was missing. Specifically it was registered to use the DLL %PROGRAMDATA%\CrossDevice\CrossDevice.Streaming.Source.dll . Not only does this path not exist, it’s also within the C:\ProgramData directory. This is a common location for all users on the system and therefore permits anyone to create directories.»)
  • An arbitrary DLL can be created there and loaded when the COM object is instantiated, potentially leading to privilege escalation. (confirmed by the publication itself: evidence; «Therefore you can create an arbitrary DLL file at that location and the COM object can be instantiated potentially leading to privilege escalation.»)
  • The authors found a COM service that runs as SYSTEM and allows custom marshaling: Shell Create Object Handler. (confirmed by the publication itself: evidence; «It turned out to be a COM service I’ve researched and exploited before, the Shell Create Object Handler object. This is an interesting COM object, in that while it runs in a SYSTEM service»)
  • A normal user can start its CreateObjectTask scheduled task. (confirmed by the publication itself: evidence; «Fortunately this task can be started by normal users»)

Primary sources:

score 56.4 out of 100 · kind: incident