Executive brief
A security vulnerability exists in the Windows Remote Procedure Call (RPC) interface, a core component used for communication between different programs on a network. An attacker located on the same local network could exploit this flaw to gain higher-level system permissions without needing a password. This could allow an unauthorized user to take control of affected systems, potentially leading to data theft or service disruption.
Technical details
An improper authentication vulnerability (CWE-287) exists in the Microsoft Windows RPC API. The flaw allows an unauthenticated attacker with adjacent network access to bypass security checks and elevate their privileges on the target system. Exploitation requires some level of user interaction, as indicated by the CVSS vector (UI:R). Successful exploitation could grant the attacker high-level access (Confidentiality, Integrity, and Availability impact are all High). Microsoft has released security updates for various versions of Windows 10, Windows 11, and Windows Server 2012 to address this issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All versions
Timeline
- 2026-07-14: disclosed: Initial disclosure by Microsoft
- 2026-07-14: advisory: NVD record published