PhantomRPC: A new privilege escalation technique in Windows RPC
If you have a service like RDP that exposes an RPC server, there many system services running as SYSTEM connect to it as RPC clients. If that service is turned off (RDP is off by default), it seems that any other process in Windows can expose the same RPC server using the same endpoint.
Now all the RPC calls from that SYSTEM processes will come to this fake server and If the process that deployed the server has SeImpersonatePrivilege, it can escalate to SYSTEM by impersonate the RPC client.
In the white paper below, I describe five exploit paths you can abuse.
PhantomRPC (LPE 0-day)
A research repository where you can find all the resources for PhantomRPC research that allows local privilege escalation.
Post #7564
137
Forwarded from 1N73LL1G3NC3