‘Unlimited Attack Vectors’—All Windows Versions At Risk From New Flaw

TL;DR AI
2 min readKey summary
Kaspersky researcher Haidar Kabibo disclosed PhantomRPC, a Windows RPC-related flaw that can let processes with impersonation rights escalate to SYSTEM.
Microsoft said it will not issue a patch, arguing the issue requires prior compromise and does not meet its criteria for a security update.
The unpatched weakness could deepen attacker control on already compromised Windows machines.
Because the flaw appears architectural, researchers warn it may affect many or all Windows versions if left unresolved.



