Vulnerabilities · 140 days ago
Any Windows process with impersonation privileges may be able to turn a local foothold into SYSTEM because the weakness sits in RPC itself, not in one broken service. A standard patch-for-one-bug response misses the larger problem: the attack surface is architectural, so new RPC-dependent services can inherit the same escalation path.
Kaspersky says PhantomRPC affects all Windows versions and lets an attacker create a fake RPC server to elevate privileges to SYSTEM. The report describes five exploitation paths from local or network service contexts and says the issue is not a single-service flaw like the Potato family.
Because the weakness is in the RPC design, the practical risk is broader than one CVE or one product line. Any process or service that relies on RPC can become another route to SYSTEM if it accepts impersonation in the wrong place.
3 sources covering this story
No Patch for New PhantomRPC Privilege Escalation Technique in Windows
A fake RPC server can be used to listen for RPC requests and impersonate the target service to elevate privileges to System.
Unpatched PhantomRPC Flaw in Windows Enables Privilege Escalation
A researcher discovered five different exploit paths that stem from an architectural weakness in Windows' Remote Procedure Call (RPC) mechanism.
Disclosing PhantomRPC – a privilege escalation vulnerability in RPC
Kaspersky researcher discovered a vulnerability in RPC architecture that enables an attacker to create a fake RPC server and escalate their privileges.
Part of the PlainSec briefing for 2026-04-28