Securelist PhantomRPC: New Windows RPC Vulnerability Enables Local Privilege Escalation
Article Content
- •PhantomRPC allows local privilege escalation to SYSTEM level in all Windows versions.
- •The vulnerability stems from architectural design flaws in Windows RPC, not a single component.
- •Microsoft has not issued a patch despite the vulnerability being disclosed.
Kaspersky has identified a significant vulnerability in the Windows Remote Procedure Call (RPC) architecture, named PhantomRPC, which allows attackers to escalate privileges locally to SYSTEM level. This vulnerability arises from architectural design flaws rather than a single faulty component, affecting all Windows versions. Researchers demonstrated five distinct exploitation paths that can be leveraged in various local or network service contexts. The issue is particularly concerning due to its unlimited potential attack vectors, as any new process or service relying on RPC could introduce additional escalation paths. Despite the severity of the findings, Microsoft has not yet issued a patch. Organizations are advised to implement monitoring and limit the use of impersonation privileges to mitigate risks. The research was presented at Black Hat Asia 2026, highlighting its importance for businesses in assessing their security posture.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…