Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
ID: a2b12800-b59a-564b-89a8-c70a3ce3a8bb
STIX ID: report--a2b12800-b59a-564b-89a8-c70a3ce3a8bb
Feed Name: Dark Reading
Threat Score
An architectural flaw in Windows RPC named PhantomRPC lets a local attacker register malicious RPC endpoints that impersonate legitimate services and escalate to SYSTEM if SeImpersonatePrivilege is present; Kaspersky released PoCs and guidance, Microsoft declined to issue a CVE or patch, and defenders are advised to monitor RPC events and restrict SeImpersonatePrivilege.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
