Microsoft Windows RPC Endpoint Mapper Service Privilege Escalation Vulnerability

Vulnerability

A use-after-free vulnerability has been identified in the RPC Endpoint Mapper Service, allowing an authorized attacker to elevate privileges locally. This vulnerability could enable the execution of code in the context of the 'NT AUTHORITY\Network Service' account.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain elevated rights on the affected system.

Remediation

Security updates addressing this vulnerability are available for various Windows versions, including Windows 10, Windows Server 2012, Windows Server 2008 R2, and Windows 11. Users should install the latest security update for their specific Windows version to mitigate this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
5.0
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.