New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions
ID: 3ef02a2e-c2b7-573c-bfb8-7c11906a0550
STIX ID: report--3ef02a2e-c2b7-573c-bfb8-7c11906a0550
Feed Name: cybersecurityNews.com
PhantomRPC is an architectural design weakness in the Windows RPC runtime (rpcrt4.dll) that allows a low-privileged process to host a malicious RPC server, impersonate a highly privileged client via RpcImpersonateClient, and escalate to SYSTEM or Administrator. Kaspersky disclosed five exploitation paths (gpupdate coercion, Microsoft Edge startup, WDI background service, ipconfig/DHCP client, and w32tm/Windows Time), reported the issue to Microsoft (no CVE or patch assigned) and published tools and mitigations including ETW-based RPC monitoring, re-enabling disabled services, and restricting SeImpersonatePrivilege.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
