Any Windows process with impersonation privileges may be able to turn a local foothold into SYSTEM because the weakness sits in RPC itself, not in one broken service. A standard patch-for-one-bug response misses the larger problem: the attack surface is architectural, so new RPC-dependent services can inherit the same escalation path. Kaspersky says PhantomRPC affects all Windows versions and lets an attacker create a fake RPC server to elevate privileges to SYSTEM. The report describes five exploitation paths from local or network service contexts and says the issue is not a single-service flaw like the Potato family. Because the weakness is in the RPC design, the practical risk is broader than one CVE or one product line. Any process or service that relies on RPC can become another route to SYSTEM if it accepts impersonation in the wrong place.
Part of the PlainSec briefing for 2026-04-28