A blog post describes exploiting CVE-2026-66804, an incomplete fix for the Windows privilege escalation vulnerability CVE-2026-50343 ('Dark Elevator'). The vulnerability involves a dangling COM object registration for CrossDevice with a missing server DLL in a world-writable directory, which attackers can abuse via custom COM marshaling to load arbitrary code into privileged processes.