Project Zero researchers report a privilege escalation bug (CVE-2026-66804) involving a dangling COM object registration for the CrossDevice component, left unfixed after a prior partial patch. The attack leverages a missing DLL in the writable C:\ProgramData path, enabling arbitrary code execution when the COM object is instantiated in a privileged process via custom COM marshaling.
Background
Project Zero is Google's security research team known for disclosing critical zero-day vulnerabilities. COM (Component Object Model) is a legacy Windows inter-process communication framework that remains widely used.
- Source
- Lobsters
- Published
- Sep 22, 2026 at 02:21 AM
- Score
- 7.0 / 10