logo

PhantomRPC: A new privilege escalation technique in Windows RPC

ID: 44b4a594-af30-57a3-be8b-3413ce1181b5

STIX ID: report--44b4a594-af30-57a3-be8b-3413ce1181b5

Feed Name: Securelist by Kaspersky

Threat Score
70/100

Date Published: 2026-04-24

Date Updated: 2026-04-29

Author: Haidar Kabibo

...
...

This research details an architectural weakness in Windows RPC/ALPC that allows processes with SeImpersonatePrivilege to deploy fake RPC servers (mimicking legitimate endpoints such as TermService, DHCP, and W32Time) and call RpcImpersonateClient to escalate privileges to SYSTEM or Administrator; the paper demonstrates five exploitation paths, provides an ETW-based detection workflow and PoC tools, and reports that Microsoft classified the issue as moderate and did not issue a patch or CVE.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.