The Unpatched Pivot: New RPC Flaw Opens Doors for Windows Privilege Escalation
ID: a3f1d723-6d48-583a-92a4-de4af903fc79
STIX ID: report--a3f1d723-6d48-583a-92a4-de4af903fc79
Feed Name: securityonline.info
Threat Score
Kaspersky researchers disclosed "PhantomRPC," an architectural local privilege escalation in Windows RPC that can let attackers coerce processes with SeImpersonatePrivilege to escalate to SYSTEM; five exploitation paths were demonstrated. Microsoft assessed the issue as moderate (requiring SeImpersonatePrivilege) and did not issue an immediate patch, so mitigations center on monitoring and restricting accounts with SeImpersonatePrivilege.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
