Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Your daily horoscope: June 17, 2026

‘Girls Like Girls’ favors nostalgia over the depth of a young queer awakening story

This special Babbel offer gives you lifetime access to lessons created by linguists

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Researcher Details Window EPM Addiction Exploit Chain Domain Privileges
Celebrities

Researcher Details Window EPM Addiction Exploit Chain Domain Privileges

By August 10, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

August 10, 2025Ravi LakshmananVulnerability/Endpoint Security

Cybersecurity researchers have presented new findings related to security issues related to communication protocols that can be abused by attackers and misused by attackers by known servers.

The vulnerability tracked as CVE-2025-49760 (CVSS score: 3.5) has been described by the Tech giant as a spoofing bug in Windows storage. Corrected in July 2025 as part of the monthly patch Tuesday update. Details of the security flaw were shared by Safebreach researcher Ron Ben Yizhak at this week’s DEF Con 33 security conference.

“External control of Windows storage filenames or paths allows certified attackers to perform spoofing on the network,” the company said in an advisory released last month.

The Windows RPC protocol uses a universally unique identifier (UUID) and endpoint mapper (EPM) to connect an RPC client to the server-registered endpoint to enable the use of dynamic endpoints in client-server communications.

The vulnerability essentially allows it to be set in what is called EPM addiction attacks, which allow unprivileged users to pose as a legal, built-in service, with the aim of maintaining a protected process to manipulate core components of the RPC protocol and authenticate against any server of the attacker’s choice.

Given that the functionality of EPM is similar to that of the Domain Name System (DNS), it maps the interface uuid to the endpoint. Only DNS resolves a domain to an IP address. Attacks play like DNS addiction.

RPC clients poisoning EPM Masquerade as legitimate RPC servers achieve local/domain privilege escalation via ESC8 attacks

“We were shocked that nothing was preventing us from registering known built-in interfaces belonging to the Core Services,” Ben Ijak said in a report she shared with Hacker News. “For example, if a Windows Defender had a unique identifier, we expected that other processes would not be able to register, but that wasn’t the case.”

Cybersecurity

“When I tried to register an interface for a service that was turned off, the client connected to me instead. This discovery was incredible. There were no security checks completed by EPM.

The heart of an attack relies on finding interfaces that are not mapped to the endpoint. Also, many services are set to “delayed start” for performance reasons, allowing them to register immediately after the system boot by making the boot process faster.

In other words, services with manual startup are a security risk, as RPC interfaces are not registered for boot. By allowing attackers to register the interface before the original service, it is effectively susceptible to hijacking.

SafeBreach flags unstable RPC services (such as storage services and StorSVC.DLL), releases a tool called RPC-Racer that can be used to operate protected process lights (PPLs), allowing machine accounts to the servers selected by the attacker.

PPL technology ensures that the operating system only loads reliable services and processes, protecting the running process from termination or infection by malicious code. It was introduced by Microsoft in the release of Windows 8.1.

At a high level, the entire attack sequence is as follows:

Creates a scheduled task that will run when the current user logs in. Registers the storage service interface to trigger the delivery optimization service to send RPC requests to the storage service, connects to the attacker’s dynamic endpoint and calls the method. Machine account credentials leaking NTLM hash stage relays forced NTLM hash to web-based certificate enrollment service (AD CS) and leaks ESC8 attacks to achieve privilege escalation

Identity Security Risk Assessment

To achieve this, you can use an offensive open source tool like Certipy to request a Kerberos Ticket Cultivation Ticket (TGT) using a certificate generated by passing NTLM information to an AD CS server, and use it to dump all the secrets from the domain controller.

Safebreach said it could further extend its EPM addiction technology to carry out interim (AITM) and denial of service (DOS) attacks by forwarding requests to the original service or registering many interfaces each to deny the request. The cybersecurity company also noted that there could be other clients and interfaces that are vulnerable to EPM addiction.

To better detect these types of attacks, security products can use event tracing in Windows (ETW), a security feature that monitors calls to RPCEPregister and records events raised by user-mode applications and kernel-mode drivers.

“You need to verify the identity of your RPC server so that SSL pinning ensures that the certificate is not only valid, but that it uses a specific public key,” says Ben Yizhak.

“The current design of the Endpoint Mapper (EPM) does not perform this validation. Without this validation, the client accepts data from unknown sources. By blindly trusting this data, the attacker can control the client’s actions and manipulate the attacker’s will.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleNASA aims to build a nuclear reactor on the moon by 2030
Next Article “Such caves were not used in normal life”: the rare finger groove of ancient people found in glittering Australian caves

Related Posts

Katie Holmes evokes ‘office siren’ at Max Mara Resort 2027 show

June 16, 2026

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Your daily horoscope: June 17, 2026

‘Girls Like Girls’ favors nostalgia over the depth of a young queer awakening story

This special Babbel offer gives you lifetime access to lessons created by linguists

Deadmau5 adopts a cat he rescued by donating to an animal shelter

Trending Posts

Deadmau5 adopts a cat he rescued by donating to an animal shelter

June 16, 2026

Ranking of all official World Cup songs

June 16, 2026

Jennifer Lopez needed to find herself again after divorce from Affleck

June 16, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.