Google Project Zero published new .NET tooling for enumerating local Windows RPC server interfaces, generating C# clients, and interacting with Local RPC services from PowerShell or C#. The release included updates tied to the Sandbox Analysis Tools, the NtObjectManager PowerShell module, and pre-generated clients in the WindowsRpcClient project, giving researchers a practical way to inspect and call undocumented or poorly documented Windows RPC endpoints.
As a demonstration, Project Zero detailed an undocumented UAC bypass in the Windows APPINFO service’s RPC interface, specifically the RAiLaunchAdminProcess method. The technique abuses CreateProcessAsUser debug flags and reuse of a thread-associated debug object to obtain a privileged handle to an elevated process, enabling code execution with elevated rights without a UAC prompt under default configurations when paired with auto-elevated binaries such as Task Manager. The report said the issue requires direct RPC access to APPINFO, may need repeated attempts because RPC thread-pool scheduling is nondeterministic, and was intentionally described as not security-serviced by Microsoft.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Zynap Labs published an article describing a malware-analysis platform that combines a kernel-mode defensive rootkit, a hypervisor layer, and persistence-triggered execution to counter sandbox evasion used by malware such as LummaC2, GuLoader, and xLoader.
Alongside the Project Zero research, Forshaw released supporting tooling through the Sandbox Analysis Tools project, the NtObjectManager PowerShell module, and pre-generated Windows RPC clients in the WindowsRpcClient GitHub project.
On his Project Zero blog, James Forshaw published .NET tooling for extracting Local Windows RPC interfaces and generating clients, and demonstrated a previously undocumented UAC bypass in the APPINFO service's RAiLaunchAdminProcess method. He also stated he would not treat it as a security-boundary vulnerability because Microsoft does not service UAC as a security boundary.
A 2019 presentation by James Forshaw was published as a reference in the source set, indicating related public research on Windows internals preceding the later Project Zero write-up.
A PACSEC 2017 presentation on ALPC/RPC was published as a reference in the source set, providing background material relevant to later Windows Local RPC research.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
7 references tracked. Mallory keeps watching after this page renders.
zynap.com
Open sourceprojectzero.google
Open sourcegithub.com
Open sourcebugs.chromium.org
Open sourcepacsec.jp
Open sourcepowerofcommunity.net
Open sourcebugs.chromium.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.