TGViewer
Fsecurity | HH Fsecurity | HH @hellohackingteam · 2.06K subscribers
Post #7564 137

Forwarded from 1N73LL1G3NC3

PhantomRPC: A new privilege escalation technique in Windows RPC

If you have a service like RDP that exposes an RPC server, there many system services running as SYSTEM connect to it as RPC clients. If that service is turned off (RDP is off by default), it seems that any other process in Windows can expose the same RPC server using the same endpoint.

Now all the RPC calls from that SYSTEM processes will come to this fake server and If the process that deployed the server has SeImpersonatePrivilege, it can escalate to SYSTEM by impersonate the RPC client.
In the white paper below, I describe five exploit paths you can abuse.

PhantomRPC (LPE 0-day)

A research repository where you can find all the resources for PhantomRPC research that allows local privilege escalation.
More from @hellohackingteam
  1. Oct 11, 2026Fsecurity | HH pinned a photo
  2. Oct 11, 2026Post #8179
  3. Oct 11, 2026Пост от меня. Всем хак 👾 Я тут в моменте наткнулся на один проект и решил сделать «кря» �…
  4. Oct 11, 2026AnyPwn Эксплойт для AnyDesk Linux, который позволяет выполнять команды на удаленном компью…
  5. Oct 10, 2026Я написал сканер уязвимостей для вайбкода и проверил им 3 800 чужих репозиториев Сегодня T…
  6. Oct 10, 2026Извлечение секретов LSA, повторное использование существующей теневой копии VSS + встроенн…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →