logo

New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions

ID: 3ef02a2e-c2b7-573c-bfb8-7c11906a0550

STIX ID: report--3ef02a2e-c2b7-573c-bfb8-7c11906a0550

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-25

Date Updated: 2026-04-25

Author: Guru Baran

...
...

PhantomRPC is an architectural design weakness in the Windows RPC runtime (rpcrt4.dll) that allows a low-privileged process to host a malicious RPC server, impersonate a highly privileged client via RpcImpersonateClient, and escalate to SYSTEM or Administrator. Kaspersky disclosed five exploitation paths (gpupdate coercion, Microsoft Edge startup, WDI background service, ipconfig/DHCP client, and w32tm/Windows Time), reported the issue to Microsoft (no CVE or patch assigned) and published tools and mitigations including ETW-based RPC monitoring, re-enabling disabled services, and restricting SeImpersonatePrivilege.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.