#phantomrpc
No Microsoft Patch—All Windows Versions Likely At Risk From PhantomRPC
No Microsoft Patch—All Windows Versions Likely At Risk From PhantomRPC
Security researchers have uncovered an unpatched Windows security bug with effectively unlimited potential attack vectors—what defenders need to know.
www.forbes.com
April 29, 2026 at 11:46 AM
If an exploit requires a compromised device, is it still an exploit?
Microsoft won't patch PhantomRPC: Feature or bug?
A researcher has detailed five ways to exploit PhantomRPC, which Microsoft rates “moderate” and does not plan to fix.
www.malwarebytes.com
April 30, 2026 at 12:00 AM
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation #cybersecurity #hacking #news #infosec #security #technology #privacy
Unpatched PhantomRPC Flaw in Windows Enables Privilege Escalation
A researcher discovered five different exploit paths that stem from an architectural weakness in Windows' Remote Procedure Call (RPC) mechanism.
www.darkreading.com
April 28, 2026 at 9:52 AM
Microsoft won’t patch PhantomRPC: Feature or bug?
www.malwarebytes.com/blog/news/20...
Microsoft won't patch PhantomRPC: Feature or bug?
A researcher has detailed five ways to exploit PhantomRPC, which Microsoft rates “moderate” and does not plan to fix.
www.malwarebytes.com
April 30, 2026 at 11:18 AM
Unpatched PhantomRPC Flaw in Windows Enables Privilege Escalation www.darkreading.com/vulnerabilit...
Unpatched PhantomRPC Flaw in Windows Enables Privilege Escalation
A researcher discovered five different exploit paths that stem from an architectural weakness in Windows' Remote Procedure Call (RPC) mechanism.
www.darkreading.com
April 27, 2026 at 5:12 PM
Unpatched Windows ‘PhantomRPC’ Flaw Allows Privilege Escalation

Researchers have published new findings PhantomRPC: A new privilege escalation technique in Windows RPC on April 24th about a has no patch as it is said to be an architecture problem, and affects all Windows systems. In response,…
Unpatched Windows ‘PhantomRPC’ Flaw Allows Privilege Escalation
Researchers have published new findings PhantomRPC: A new privilege escalation technique in Windows RPC on April 24th about a has no patch as it is said to be an architecture problem, and affects all Windows systems. In response, three cybersecurity experts offer perspective. Sameed Aijas Ahmed Khan with Dubai-based Secure.com: "PhantomRPC is a meaningful finding because it sits at the architectural level of Windows, not in an isolated feature that can simply be switched off or patched.
itnerd.blog
April 27, 2026 at 8:15 PM
New Windows RPC flaw (PhantomRPC) allows local privilege escalation to SYSTEM on all Windows versions—and Microsoft hasn't patched it yet. Five exploitation paths demonstrated at Black Hat Asia.

https://www.youtube.com/watch?v=krztD4lJK30

#cybersecurity #infosec
August 25, 2026 at 7:30 AM
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation: https://bit.ly/41VMsLx by Elizabeth Montalbano
Unpatched PhantomRPC Flaw in Windows Enables Privilege Escalation
A researcher discovered five different exploit paths that stem from an architectural weakness in Windows' Remote Procedure Call (RPC) mechanism.
bit.ly
April 27, 2026 at 9:02 PM
Falha inédita no Windows permite que invasores tomem controle total do sistema
Pesquisadores da Kaspersky identificaram uma vulnerabilidade no mecanismo de comunicação interna do Windows que permite a um invasor elevar privilégios até o nível SYSTEM. Batizada de PhantomRPC pelo pesquisador Haidar Kabibo, a falha está no RPC, protocolo usado por processos do sistema operacional para se comunicar entre si. O problema é que o Windows não verifica se o servidor RPC com quem um processo tenta se conectar é legítimo, o que abre espaço para a criação de servidores falsos que imitam serviços reais. Um invasor que já controle um processo com privilégio intermediário, como os que rodam sob as contas Network Service ou Local Service, pode usar esse servidor falso para interceptar requisições de processos mais privilegiados e assumir sua identidade. O pesquisador demonstrou cinco caminhos distintos para executar o ataque, envolvendo serviços como Group Policy, WDI e DHCP Client, além do navegador Microsoft Edge. A Kaspersky reportou a falha à Microsoft em setembro de 2025.
www.tecmundo.com.br
April 30, 2026 at 8:06 PM
PhantomRPC: A new privilege escalation technique in Windows RPC securelist.com/phantomrpc-r...
Disclosing PhantomRPC – a privilege escalation vulnerability in RPC
Kaspersky researcher discovered a vulnerability in RPC architecture that enables an attacker to create a fake RPC server and escalate their privileges.
securelist.com
April 24, 2026 at 4:28 PM
PhantomRPC: un bug di sicurezza critico in Windows RPC, ma Microsoft non rilascia fix

📌 Link all'articolo : www.redhotcyber.com/post/phantom...

A cura di Bajram Zeqiri

#redhotcyber #news #cybersecurity #hacking #windows #vulnerabilita #phantomrpc
April 28, 2026 at 4:43 AM
Microsoft won’t patch PhantomRPC: Feature or bug? Malwarebytes Labs: www.malwarebytes.com/blog/news/20...
Microsoft won't patch PhantomRPC: Feature or bug?
A researcher has detailed five ways to exploit PhantomRPC, which Microsoft rates “moderate” and does not plan to fix.
www.malwarebytes.com
April 29, 2026 at 1:32 PM
Falha inédita no Windows permite que invasores tomem controle total do sistema
A Kaspersky divulgou uma vulnerabilidade no mecanismo de comunicação interna do Windows que permite elevar privilégios até o nível SYSTEM. A falha foi batizada de PhantomRPC pelo pesquisador Haidar Kabibo. Afeta potencialmente todas as versões do Windows e ainda não tem correção prevista. O mecanismo usado para processos "conversarem" no Windows é o RPC, sigla para Remote Procedure Call. Basicamente, ele permite que um processo peça a outro que execute uma função, mesmo em contextos separados. É assim que boa parte dos serviços internos do Windows funcionam. O Windows também tem um recurso chamado impersonation, ou impersonação. Ele permite que um serviço assuma temporariamente a identidade de outro processo para realizar uma tarefa. Um serviço de impressão, por exemplo, pode agir como o usuário que enviou o documento para acessar determinados arquivos. No modelo RPC do Windows, um processo cliente envia requisições a um servidor identificado por um UUID e um endpoint. O PhantomRPC abusa dessa arquitetura ao permitir que um servidor falso ocupe o mesmo endpoint de um serviço legítimo sem que o sistema operacional valide a autenticidade da conexão. Imagem: Kaspersky. O problema é que o Windows não verifica se o servidor RPC com quem um processo tenta se comunicar é legítimo. Um invasor pode criar um servidor RPC falso fingindo ser um serviço real. O sistema operacional não barra essa conexão. ## Como o ataque funciona na prática Para explorar o PhantomRPC, o atacante precisa comprometer um serviço com privilégio intermediário, como os que rodam sob as contas Network Service ou Local Service. Essas contas têm uma permissão chamada SeImpersonatePrivilege, que autoriza um processo a impersonar outro. Com esse acesso, o atacante sobe um servidor RPC falso que imita um serviço legítimo. Quando um processo mais privilegiado tenta se comunicar com o serviço real e não consegue, a requisição vai parar no servidor falso. Ele então assume a identidade do processo privilegiado e age em seu nome. O pesquisador demonstrou cinco caminhos diferentes para executar esse ataque. O serviço Group Policy Client roda sob a conta NT AUTHORITY\SYSTEM, o nível mais alto de privilégio no Windows. É ele quem faz a chamada RPC interceptada pelo servidor falso no principal caminho de exploração documentado pela Kaspersky. Imagem: Kaspersky. ## Cinco formas de escalar privilégios O primeiro caminho envolve o serviço Group Policy, que roda com privilégio SYSTEM. Quando o comando gpupdate /force é executado, esse serviço tenta se comunicar com o TermService, o serviço de área de trabalho remota. O TermService fica inativo por padrão, então o servidor falso intercepta a requisição e o atacante obtém acesso SYSTEM. O segundo caminho não exige interação alguma. O serviço WDI, responsável por diagnósticos do sistema, faz chamadas automáticas ao TermService a cada 5 a 15 minutos. O atacante apenas aguarda a próxima chamada para impersonar o contexto SYSTEM. O terceiro caminho envolve o Microsoft Edge. Ao iniciar, o navegador faz uma chamada RPC ao TermService. Se um administrador abrir o Edge, o servidor falso intercepta a requisição e eleva os privilégios do atacante de Network Service para Administrator. O TermService, serviço responsável pela área de trabalho remota do Windows, fica inativo por padrão. Essa condição é explorada pelo PhantomRPC para redirecionar chamadas RPC a um servidor falso. Imagem: Kaspersky. Os dois últimos caminhos partem de uma conta Local Service. Um explora o serviço DHCP Client e aguarda um administrador rodar o ipconfig. O outro abusa do executável w32tm.exe, de sincronização de horário, que tenta se conectar a um endpoint RPC inexistente no serviço legítimo. O atacante cria um servidor falso que expõe justamente esse endpoint. ## Microsoft não vai corrigir agora A Kaspersky relatou a vulnerabilidade ao Microsoft Security Response Center em setembro de 2025. Vinte dias depois, a Microsoft classificou o problema como severidade moderada. A justificativa foi que o ataque exige a permissão SeImpersonatePrivilege no processo do atacante. Sem CVE atribuído e sem previsão de patch, a Kaspersky publicou a pesquisa após o fim do período de embargo. O pesquisador recomenda monitorar exceções de RPC, manter serviços legítimos ativos e restringir a permissão SeImpersonatePrivilege a processos que realmente precisam dela. Acompanhe o TecMundo nas redes sociais. Para mais notícias de segurança e tecnologia, inscreva-se em nossa newsletter e canal do YouTube.
www.tecmundo.com.br
April 30, 2026 at 8:09 PM
Kaspersky recently disclosed PhantomRPC, a privilege escalation technique affecting all Windows versions (tested on Server 2022/2025)
Kaspersky recently disclosed PhantomRPC, a privilege escalation technique affecting all Windows vers
www.reddit.com
April 28, 2026 at 7:02 PM
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
www.darkreading.com
April 27, 2026 at 11:44 PM
A new Windows RPC flaw, PhantomRPC, allows fake RPC servers to impersonate privileged services and escalate to System via multiple components including TermService and Group Policy. #PhantomRPC #WindowsRPC #Kaspersky
No Patch for New PhantomRPC Privilege Escalation Technique in Windows
Kaspersky researcher Haidar Kabibo discovered an architectural weakness in Windows RPC, named PhantomRPC, that allows attacker-deployed fake RPC servers to impersonate privileged services and elevate privileges to System. The flaw affects multiple Windows components and services (including TermService, Group Policy, DHCP Client, Windows Time, WDI, and Network/Local Service accounts), creating numerous...
www.hendryadrian.com
April 28, 2026 at 12:15 PM
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
A researcher discovered five different exploit paths that stem from an architectural weakness in how Windows' Remote Procedure Call (RPC) mechanism handles connections to unavailable services.
www.darkreading.com
April 27, 2026 at 4:07 PM
New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions
New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions
PhantomRPC, a newly identified architectural vulnerability in Windows Remote Procedure Call (RPC) that enables local privilege escalation to SYSTEM-level access, potentially affecting every version of Windows. The research was presented by Kaspersky application security specialist Haidar Kabibo at Black Hat Asia 2026 on April 24 and details five distinct exploitation paths, none of which have received a patch from Microsoft. PhantomRPC is not a classic memory corruption bug or a logic flaw in a single component. Instead, it exploits an architectural design weakness in how the Windows RPC runtime (rpcrt4.dll) handles connections to unavailable RPC servers. When a highly privileged process attempts an RPC call to a server that is offline or disabled, the RPC runtime does not verify whether the responding server is legitimate. This means an attacker who controls a low-privileged process, such as one running under NT AUTHORITY\NETWORK SERVICE, can deploy a malicious RPC server that mimics a legitimate endpoint and intercept those calls. Malicious RPC Server (Kaspersky) The core abuse relies on the RpcImpersonateClient API. When a privileged client connects to the fake server with a high impersonation level, the attacker’s server calls this API to assume the client’s security context — escalating from a low-privileged service account directly to SYSTEM or Administrator. Five Exploitation Paths Researchers identified five concrete attack scenarios: gpupdate.exe coercion — Triggering gpupdate /force causes the Group Policy Client service (running as SYSTEM) to make an RPC call to TermService. If TermService is disabled, the attacker’s fake RPC server intercepts the call, yielding SYSTEM-level access. Microsoft Edge startup — When msedge.exe launches, it triggers an RPC call to TermService with a high impersonation level. An attacker waiting with a spoofed endpoint can escalate from Network Service to Administrator without any coercion. WDI background service — The Diagnostic System Host (WdiSystemHost), running as SYSTEM, periodically polls TermService every 5–15 minutes. No user interaction is required; the attacker simply waits for the automated call. ipconfig.exe and DHCP Client — Executing ipconfig.exe triggers an internal RPC call to the DHCP Client service. With DHCP disabled and a fake server in place, a Local Service attacker escalates to Administrator. w32tm.exe and Windows Time — The Windows Time executable first attempts to connect to a nonexistent named pipe \PIPE\W32TIME . An attacker can expose this endpoint without disabling the legitimate W32Time service, then impersonate any privileged user who runs the binary. Microsoft’s Response — No Patch The vulnerability was reported to Microsoft Security Response Center (MSRC) on September 19, 2025. Microsoft responded 20 days later, classifying the issue as moderate severity on the grounds that the attack requires SeImpersonatePrivilege a privilege already held by default by Network Service and Local Service accounts. No CVE was assigned, and the case was closed without a scheduled fix, reads the Kaspersky report . Until a patch is issued, defenders can take the following steps: Enable ETW-based RPC monitoring to detect RPC_S_SERVER_UNAVAILABLE errors (Event ID 1) combined with high impersonation levels from privileged processes. Enable disabled services such as TermService where feasible, so legitimate endpoints are occupied and cannot be hijacked. Restrict SeImpersonatePrivilege to only those processes that strictly require it; do not grant it to custom or third-party applications. Kaspersky has released all tools used in the research framework via the PhantomRPC GitHub repository , allowing organizations to audit their own environments for exploitable RPC call patterns. Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories. The post New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions appeared first on Cyber Security News .
cybersecuritynews.com
April 25, 2026 at 5:56 PM
Security Check-in Quick Hits: PhantomRPC Windows Escalation, Litecoin Zero-Day DoS, CISA KEV Alerts, and Active WordPress Plugin Attacks rodtrent.substack.co...

#Security #Cybersecurity
April 26, 2026 at 6:00 PM
A researcher discovered five different exploit paths that stem from an architectural weakness in how Windows' Remote Procedure Call (RPC) mechanism handles connections to unavailable services. www.darkreading.com/vulnerabilit...
Unpatched PhantomRPC Flaw in Windows Enables Privilege Escalation
A researcher discovered five different exploit paths that stem from an architectural weakness in Windows' Remote Procedure Call (RPC) mechanism.
www.darkreading.com
April 28, 2026 at 3:00 PM
Questa vulnerabilità sottovalutata in Windows può dare accesso totale al sistema: PhantomRPC
PhantomRPC mostra come un comportamento "by design" di Windows possa esser...
https://www.ilsoftware.it/phantomrpc-falla-rpc-accesso-privilegi-system-windows/
April 29, 2026 at 10:00 AM
Disclosing PhantomRPC – a privilege escalation vulnerability in RPC
Disclosing PhantomRPC – a privilege escalation vulnerability in RPC
securelist.com
April 29, 2026 at 11:24 PM
Disclosing PhantomRPC – a privilege escalation vulnerability in RPC
Disclosing PhantomRPC – a privilege escalation vulnerability in RPC
securelist.com
April 25, 2026 at 8:24 PM