Impact
Missing authentication for a critical function in the Windows Remote Procedure Call (RPC) API allows an attacker who has local or authenticated access to elevate privileges. By invoking the privileged RPC method without required authentication checks, the attacker can gain higher system rights, enabling modification of system configuration, installing software, or accessing restricted data. The weakness is identified as CWE-306, representing a missing authentication check for protected functionality.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including core installations where listed. The vulnerability exists in the default Windows Remote Procedure Call (RPC) service on each of these versions.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring an account with some level of system access to exploit the missing authentication in the RPC API. The flaw permits a privileged escalation that could lead to full system compromise once the attacker gains higher rights. Because the vulnerability is broad across many OS releases, organizations should prioritize patching to mitigate this risk.
OpenCVE Enrichment