Kaspersky disclosed PhantomRPC, a Windows RPC architectural weakness that can let a low-privileged local attacker escalate to SYSTEM or Administrator by standing up a fake RPC server when the legitimate server is unavailable. The flaw affects RPC client-server interactions over ALPC and named pipes, where a privileged client can connect to an attacker-controlled endpoint exposing the same interface and endpoint; if the attacker already has a service account with SeImpersonatePrivilege, such as Network Service or Local Service, they can call RpcImpersonateClient and assume the identity of the higher-privileged client. Researchers said the behavior stems from rpcrt4.dll accepting responses from spoofed servers under these failure conditions and described it as an architectural issue affecting potentially all Windows versions.
The research detailed five exploitation paths, including coercing the Group Policy service through a fake TermService endpoint, waiting for Microsoft Edge or WdiSystemHost to contact TermService, abusing ipconfig.exe when the DHCP Client service is disabled, and abusing w32tm.exe through a nonexistent W32Time pipe. Proof-of-concept testing was reported on Windows Server 2022 and Windows Server 2025. Microsoft was notified in 2025 but classified the issue as moderate severity, assigned no CVE, and did not plan an immediate patch. Kaspersky recommended ETW-based monitoring for RPC_S_SERVER_UNAVAILABLE failures, reducing unnecessary SeImpersonatePrivilege, enabling disabled services where practical, and using released GitHub assessment tools to identify exposed RPC client-server mismatches.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Kaspersky disclosed PhantomRPC at Black Hat Asia 2026, presenting the vulnerability as a local privilege-escalation technique affecting potentially all Windows versions. The presentation highlighted five exploitation paths and shared mitigation guidance and assessment tools.
Securelist published research describing PhantomRPC as an architectural weakness in Windows RPC that can let a low-privileged attacker-controlled fake RPC server impersonate privileged clients and escalate to SYSTEM or administrator. The disclosure said the issue affects all Windows versions, documented five exploitation paths, and described an ETW-based detection methodology.
Kaspersky researchers reported the PhantomRPC Windows RPC privilege-escalation issue to Microsoft in September 2025. Microsoft later classified the issue as moderate severity, did not assign a CVE, and did not plan an immediate patch.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcecybersecuritynews.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.