logo

Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation

ID: a2b12800-b59a-564b-89a8-c70a3ce3a8bb

STIX ID: report--a2b12800-b59a-564b-89a8-c70a3ce3a8bb

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Elizabeth Montalbano

...
...

An architectural flaw in Windows RPC named PhantomRPC lets a local attacker register malicious RPC endpoints that impersonate legitimate services and escalate to SYSTEM if SeImpersonatePrivilege is present; Kaspersky released PoCs and guidance, Microsoft declined to issue a CVE or patch, and defenders are advised to monitor RPC events and restrict SeImpersonatePrivilege.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.