Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343)
Summary
The article analyzes the Windows 11 Local Privilege Escalation CVE-2026-50343, showing how a normal user can force the InstallService to load an attacker-controlled DLL into the SYSTEM process to obtain an interactive SYSTEM shell. It describes two bugs enabling exploitation: a writable StaticPluginMap registry entry and a user-plantable COM server DLL path under ProgramData. It also includes a high-level exploit chain, PoC reference, and disclosure timeline.