Multiple public write-ups detailed how Windows service and RPC design flaws enabled local privilege escalation, sandbox escape, and in some cases reliable code execution. Research on the Windows SSDP service linked FC_BINDING_CONTEXT misuse to CVE-2025-48815, showing that a context handle from one RPC interface could be passed into another interface expecting a different type and ultimately abused to call CloseHandle on an unintended handle. Separate analysis of the Windows telephony service described CVE-2024-26230 as a use-after-free in tapisrv caused by improper ownership validation of RPC-managed objects, allowing a dangling pointer to be reclaimed with attacker-controlled data and steered toward LoadLibraryW despite XFG protections. Earlier Windows RPC research also covered Storage Service bugs CVE-2019-0983 and CVE-2019-0998, where file-copy, directory, and ACL logic exposed through RPC could be abused to overwrite privileged files or alter their security descriptors.
Other disclosures showed the same pattern across Windows subsystems. Analysis of CVE-2022-22715 in npfs.sys demonstrated that malformed LOCAL\ named pipe paths could trigger integer overflow and out-of-bounds kernel writes, enabling escape from the Adobe Reader AppContainer sandbox and escalation to kernel read/write. Research into CVE-2021-1648 in splwow64 described bypasses in printer-handle validation and an arbitrary address read, while older work on CVE-2018-8550 examined COM DfMarshal abuse for elevation of privilege through privileged unmarshaling paths. Related reporting also highlighted Microsoft hard-link mitigations and a Citrix restricted-desktop breakout that relied on allowed scripting components rather than a zero-day, underscoring how weak validation, unsafe object handling, and incomplete execution controls repeatedly exposed high-impact privilege boundaries on Windows.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
29 events from the most recent confirmed update back to the earliest known activity.
The researcher began investigating a class of Windows RPC type-confusion issues while reviewing the attack surface of Windows HTTP Services. This work later led to multiple CVEs involving cross-type context-handle usage.
Microsoft patched CVE-2024-26230 in April 2024. The vulnerability was a use-after-free in the Windows telephony service caused by improper ownership validation for GOLD objects.
The author publicly disclosed technical details of CVE-2022-22715 in a blog post. The write-up described the integer overflow and underflow in NpTranslateContainerLocalAlias and its use for Adobe Reader sandbox escape.
Microsoft released a patch for the npfs.sys vulnerability and assigned CVE-2022-22715. The fix changed size calculations to safer integer handling and added a final size bound check.
The Windows Named Pipe File System vulnerability CVE-2022-22715 was reported to Microsoft via TianfuCup 2021. The bug affected npfs.sys and enabled sandbox escape from AppContainer or restricted contexts.
Microsoft released the patch for CVE-2021-1648 in the January 2021 Patch Tuesday release. The issue affected the Windows splwow64 printing service and merged multiple bypass and disclosure cases.
A bounty was awarded for the reported splwow64 vulnerability. This occurred while the patch was still pending.
MSRC decided to put off the patch for the splwow64 issue. The article says Microsoft had planned to patch it in October 2020 but delayed the fix by four months.
The author reported the Windows splwow64 vulnerability later tracked as CVE-2021-1648 to MSRC. The issue involved bypasses of earlier printer-handle validation and additional information disclosure cases.
The author received a bounty after reporting CVE-2019-0983 and CVE-2019-0998. This followed Microsoft's patching of the issues.
Microsoft released patches for the StorSvc vulnerabilities in May 2019. The fixes added client impersonation around CopyFileW for CVE-2019-0983 and directory verification before SetNamedSecurityInfoW for CVE-2019-0998.
Microsoft reproduced the two StorSvc vulnerabilities after they were reported. This validated the file overwrite and DACL modification issues in the Windows Storage Service.
k0shl reported two Windows Storage Service local privilege escalation vulnerabilities, CVE-2019-0983 and CVE-2019-0998, to Microsoft. Both issues involved privileged file operations reachable through StorSvc RPC paths.
MSRC assigned case 42121 to Project Zero issue 1428 and case 42122 to issue 1427. This formalized Microsoft's internal tracking of the StorSvc reports.
MSRC acknowledged receipt of the Project Zero StorSvc reports. This confirmed Microsoft had received the vulnerability submission for review.
Google Project Zero submitted a Windows Elevation of Privilege vulnerability in StorSvc SvcMoveFileInheritSecurity to MSRC. The flaw allowed a normal user to assign an arbitrary security descriptor to an arbitrary file via a hardlinked file move.
Cognisys assessed a restricted Citrix desktop and bypassed controls by executing a .bat file that generated and ran a VBScript through wscript.exe, which launched PowerShell indirectly. The breakout yielded a fully interactive PowerShell session without a zero-day exploit.
Using NtObjectManager to identify RPC servers with multiple FC_BINDING_CONTEXT parameters, the researcher found additional cases tracked as CVE-2025-53143 and CVE-2025-54104. The article presents crash-inducing examples discovered through the same analysis approach.
The research uncovered CVE-2025-48815 in ssdpsrv, where a context handle from SSDPOpenRpc could be passed to RemoveSyncHandle as a different handle type. This let the service close an arbitrary handle accessible in its process context.
Microsoft introduced a mitigation in Windows Insider Preview build 18898.1000 to stop ordinary users from creating hard links to privileged files. The NTFS change enforced real target access checks during hard-link creation.
A full proof of concept for the StorSvc vulnerability was uploaded publicly. The PoC demonstrated the arbitrary file security descriptor overwrite path.
Microsoft later marked the remaining StorSvc issue as fixed in its advisory for CVE-2018-0983. This indicated a subsequent patch addressed the unfixed edge case from Project Zero issue 1428.
The StorSvc issue became public after the disclosure timeline elapsed. Public disclosure occurred because the reporter determined the edge case had not been fixed.
After reviewing Microsoft's February patch, the reporter concluded that issue 1427 was fixed but issue 1428 remained unfixed. This established that the original remediation was incomplete.
Microsoft issued a public fix for CVE-2018-0826. Project Zero later determined this patch fixed issue 1427 but not the separate edge case in issue 1428.
MSRC assigned CVE-2018-0826 to the StorSvc vulnerability track. The CVE assignment identified the issue for public patching and advisory purposes.
MSRC confirmed to Project Zero that the StorSvc issues were on track for a February 2018 fix. This was an update on Microsoft's remediation schedule.
MSRC reported that issue 1428 had been reproduced and was being tracked as a duplicate of issue 1427. Microsoft treated the two StorSvc issues as part of the same remediation track.
MSRC reported that Project Zero issue 1427 had been reproduced and was under investigation for a security release. This established that Microsoft had validated at least the related StorSvc bug.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
whereisk0shl.top
Open sourcelabs.cognisys.group
Open sourcewhereisk0shl.top
Open sourcejlajara.gitlab.io
Open sourcewhereisk0shl.top
Open sourcebugs.chromium.org
Open sourcesaelo.github.io
Open sourcedecoder.cloud
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.