Threat reportVulnerabilityTL-2026-0420

PhantomRPC — Unpatched Windows RPC Local Privilege Escalation to SYSTEM via Fake RPC Server Impersonation (Kaspersky)

highACTIVE

PhantomRPC — Unpatched Windows RPC Local Privilege (TL-2026-0420), also tracked as PhantomRPC, is a high-severity software vulnerability scored CVSS 7.8, first published 2026-04-24. It has no confirmed attribution, affects Microsoft Windows Server 2025, maps to 17 MITRE ATT&CK techniques (T1007, T1036.005, T1057), and is covered by 9 detection rules and 20 indicators of compromise.

CVSS
7.8/10High
CVEs
0None referenced
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-0420

Threat ID
TL-2026-0420
Also known as
PhantomRPC, MSRC Case 101749
Severity
HIGH
CVSS
7.8 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, financial, healthcare, technology, defense, energy, manufacturing, education, telecommunications, critical infrastructure
Target regions
Global
Detection rules
9
Indicators of compromise
20

Malware and tooling in PhantomRPC — Unpatched Windows RPC Local Privilege

Malware and tooling: Microsoft-Windows-RPC ETW Provider GUID

How PhantomRPC — Unpatched Windows RPC Local Privilege works

PhantomRPC is a novel local privilege escalation technique disclosed by Kaspersky Security Services researcher Haidar Kabibo on 2026-04-24. An attacker with SeImpersonatePrivilege stands up a malicious RPC server impersonating legitimate but unavailable Windows services (Terminal Services, DHCP Client, Windows Time, gpsvc, WdiSystemHost), waits for privileged clients to connect, then calls RpcImpersonateClient to assume SYSTEM context. Microsoft (MSRC Case 101749) declined to patch and refused to assign a CVE, classifying the issue as moderate, so Windows Server 2022/2025 and effectively all current Windows versions remain exposed. Public PoC and an ETW-based detection framework are available on GitHub (klsecservices/PhantomRPC).

PhantomRPC is an architectural weakness in Windows Remote Procedure Call (RPC) that permits local privilege escalation from any account holding SeImpersonatePrivilege (default for Local Service, Network Service, and IIS/MSSQL service accounts) up to NT AUTHORITY\SYSTEM. The technique was published on 2026-04-24 by Haidar Kabibo of Kaspersky Security Services (GReAT / SecureList).

Root cause: Windows RPC does not verify the legitimacy or identity of RPC servers before a client negotiates an impersonation-level (RPC_C_IMP_LEVEL_IMPERSONATE or RPC_C_IMP_LEVEL_DELEGATE) connection. When a well-known Windows service is not running, the RPC runtime returns RPC_S_SERVER_UNAVAILABLE (0x800706BA) to clients. An attacker with SeImpersonatePrivilege can register a malicious endpoint bound to the same interface UUID and protocol sequence (ncalrpc / ncacn_np named pipes such as \PIPE\W32TIME and \PIPE\W32TIME_ALT) before the legitimate service starts, or in scenarios where the service never runs. When a privileged client process makes an RPC call, it connects to the attacker's endpoint. The malicious server then invokes RpcImpersonateClient to obtain a primary impersonation token for the calling identity, which can be elevated to SYSTEM via standard token-theft primitives (CreateProcessWithTokenW / DuplicateTokenEx → CreateProcessAsUserW).

Kaspersky documented five reliable coercion paths on fully-patched Windows Server 2022 and Windows Server 2025: (1) Group Policy Client (gpsvc) — triggered by 'gpupdate /force', yielding a SYSTEM token; (2) Terminal Services (TermService) — triggered by launching msedge.exe, yielding the current user's token, useful for session hijacking; (3) Diagnostic System Host (WdiSystemHost/WDI) — autonomous trigger every 5–15 minutes, SYSTEM token; (4) DHCP Client service — triggered by 'ipconfig /renew' or 'ipconfig /release', administrator token; (5) Windows Time (W32Time) — triggered by 'w32tm.exe /resync', exposes named pipes \PIPE\W32TIME and \PIPE\W32TIME_ALT.

Disclosure history: the vulnerability was reported to MSRC on 2025-09-19 as Case 101749. On 2025-10-10 Microsoft declined to patch, classifying the issue as moderate severity because SeImpersonatePrivilege is required, and refused to assign a CVE. Kaspersky honored a multi-month embargo before publishing on 2026-04-24. Because Microsoft has no plans to fix the architectural flaw, all present and future Windows versions are assumed vulnerable.

Detection: Kaspersky released an ETW-based framework that captures events from the Microsoft-Windows-RPC provider (GUID {6ad52b32-d609-4be9-ae07-ce8dae937e39}). Event ID 5 (RPC start) and Event ID 1 (RPC stop) are correlated by ActivityID; a stop event carrying status 0x800706BA (RPC_S_SERVER_UNAVAILABLE) against a sensitive interface UUID from a privileged caller is the primary signal that a client has just failed to reach a legitimate service — the exact window in which a PhantomRPC server would take over. The klsecservices/PhantomRPC GitHub repository ships a Python enricher (enricher.py) that joins RPC interface names from interfaces.json and filters on impersonation level, endpoint, and client privilege.

Impact: Although SYSTEM is reachable today from Local Service / Network Service via other public primitives (the Potato family, SCMUACBypass, etc.), PhantomRPC is notable because (a) no patch is forthcoming, (b) it works against the latest Server 2022/2025 builds, (c) it blends into normal RPC traffic and does not require exploit shellcode, and (d) the gpsvc / WDI paths allow passive SYSTEM acquisition with no user interaction. Blue teams should treat this as an evergreen post-exploitation primitive and deploy ETW detection coverage immediately.

MITRE ATT&CK techniques used in TL-2026-0420

Discovery

T1007 System Service Discovery; T1057 Process Discovery; T1069 Permission Groups Discovery

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1574 Hijack Execution Flow

Execution

T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1559 Inter-Process Communication; T1569.002 System Services: Service Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1134 Access Token Manipulation; T1134.001 Access Token Manipulation: Token Impersonation/Theft; T1134.002 Access Token Manipulation: Create Process with Token; T1134.003 Access Token Manipulation: Make and Impersonate Token; T1548 Abuse Elevation Control Mechanism

Resource Development

T1587.004 Develop Capabilities: Exploits; T1588.005 Obtain Capabilities: Exploits

Credential Access

T1649 Steal or Forge Authentication Certificates

Affected products and versions in PhantomRPC — Unpatched Windows RPC Local Privilege

  • Microsoft — Windows Server 2025
    Vulnerable versions: all builds as of 2026-04-24
  • Microsoft — Windows Server 2022
    Vulnerable versions: all builds as of 2026-04-24
  • Microsoft — Windows Server 2019
    Vulnerable versions: assessed vulnerable — shares RPC architecture
  • Microsoft — Windows 11
    Vulnerable versions: assessed vulnerable — shares RPC architecture
  • Microsoft — Windows 10
    Vulnerable versions: assessed vulnerable — shares RPC architecture

Remediation for PhantomRPC — Unpatched Windows RPC Local Privilege

Patches

  • No patch available. Microsoft MSRC Case 101749 declined on 2025-10-10; no CVE assigned. Microsoft treats the underlying architectural behavior as a by-design consequence of SeImpersonatePrivilege.

Immediate actions

  • Audit accounts and services holding SeImpersonatePrivilege; revoke from any non-system or custom service accounts (e.g., legacy IIS app pools, ad-hoc scheduled tasks).
  • Deploy ETW detection for Microsoft-Windows-RPC provider GUID {6ad52b32-d609-4be9-ae07-ce8dae937e39}: alert on Event ID 1 (RPC stop) with status 0x800706BA (RPC_S_SERVER_UNAVAILABLE) against sensitive interface UUIDs followed by successful RPC impersonation.
  • Enable all referenced RPC services where operationally safe (Terminal Services, Windows Time, DHCP Client, gpsvc, Diagnostic System Host) to shrink the attack surface of unavailable endpoints that can be squatted by a fake server.
  • Deploy the Kaspersky detection toolkit (klsecservices/PhantomRPC toolset/enricher.py + interfaces.json) into SOC triage workflows or rebuild equivalent detections in your SIEM.
  • Hunt for unexpected ncacn_np / ncalrpc listeners registered by non-system processes on endpoints (Get-WinEvent / ETW / Sysmon Event ID 18 Pipe Created).
  • Restrict and monitor creation of named pipes matching known service patterns (\\.\\pipe\\W32TIME, \\.\\pipe\\W32TIME_ALT, \\.\\pipe\\gpapi, \\.\\pipe\\TermSrv_API_service).

Workarounds

  • Disable or isolate the high-value coercion paths: unused Terminal Services, Windows Time, and WDI trigger RPC client connections that attackers rely on — keep services that must exist running so their endpoints cannot be squatted.
  • Run msedge.exe (and other browsers that trigger TermService RPC) only from low-privilege interactive sessions so that the resulting impersonation token is not itself privileged.
  • Block or audit 'gpupdate /force' invocations outside scheduled maintenance windows to reduce opportunistic gpsvc coercion.
  • Use AppLocker / WDAC to prevent unsigned binaries from registering RPC endpoints on sensitive systems (Tier 0, DCs, ADFS, issuing CAs).

Longer-term hardening

  • Apply least-privilege design principles: scope SeImpersonatePrivilege only to vetted Microsoft service accounts; never grant to interactive or third-party service accounts.
  • Adopt Credential Guard, LSA protection (RunAsPPL=1), and Protected Process Light (PPL) on privileged RPC clients to reduce post-impersonation token abuse.
  • Enable Windows Defender Attack Surface Reduction (ASR) rule 'Block credential stealing from lsass.exe' (D1E49AAC-8F56-4280-B9BA-993A6D77406C) as a partial mitigation for downstream token abuse.
  • Implement continuous ETW-based RPC telemetry collection with long-term retention; correlate RPC_S_SERVER_UNAVAILABLE spikes with process creation events.
  • Review and remove legacy service accounts that run with SeImpersonatePrivilege but do not require it (IIS classic app pools, custom Windows services running as NT AUTHORITY\NETWORK SERVICE).
  • Adopt Just-In-Time (JIT) administration (Microsoft PAW / Azure PIM) so that SYSTEM-reachable footholds expire automatically.

Weaknesses (CWE) in PhantomRPC — Unpatched Windows RPC Local Privilege

CWE-287, CWE-290, CWE-345, CWE-346, CWE-284, CWE-269

Timeline of PhantomRPC — Unpatched Windows RPC Local Privilege

  • Haidar Kabibo (Kaspersky Security Services) privately discloses PhantomRPC to Microsoft Security Response Center (MSRC Case 101749).
  • Microsoft declines to patch PhantomRPC, classifies the issue as moderate severity on the basis that SeImpersonatePrivilege is required, refuses to assign a CVE, and closes MSRC Case 101749.
  • Threadlinqs Intelligence opens TL-2026-0420 for PhantomRPC tracking, simulation, and detection coverage.
  • Kaspersky releases an ETW-based detection framework using the Microsoft-Windows-RPC provider GUID {6ad52b32-d609-4be9-ae07-ce8dae937e39} and logman capture commands alongside the PoC.
  • klsecservices/PhantomRPC repository published on GitHub under MIT license; includes C-language PoC servers (TERM, DHCP, TIME), enricher.py ETW post-processor, and interfaces.json RPC interface database.
  • Kaspersky publishes the PhantomRPC technical analysis on Securelist, ending the coordinated-disclosure embargo period.
  • As of 2026-05-29, PhantomRPC remains a live, unpatched Windows RPC privilege-escalation primitive: Microsoft (MSRC 101749) refused to patch, declined a CVE, and the May 2026 Patch Tuesday shipped no fix, so all Windows versions including Server 2025 stay exposed. A public Kaspersky PoC persists and the by-design flaw is an evergreen SYSTEM-LPE technique, though no in-the-wild abuse is yet reported.

Sources cited for PhantomRPC — Unpatched Windows RPC Local Privilege

Detection coverage for TL-2026-0420

As of 2026-04-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0420 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats