DEF CON 33 - You snooze you lose: RPC Racer winning RPC endpoints against services - Ron Ben Yizhak

DEF CON 33 - You snooze you lose: RPC Racer winning RPC endpoints against services - Ron Ben Yizhak

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 35:34

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Security researcher Ron Benitra discovered EPM poisoning, a vulnerability in Windows RPC protocol that allows attackers to hijack RPC endpoints without proper authentication checks, potentially leading to privilege escalation and machine account compromise 7:57.

Key Takeaways:
• RPC protocol uses an endpoint mapper (EPM) to resolve interface UUIDs to endpoints, but lacks security verification of who can register interfaces 4:38-5:11
• EPM poisoning allows attackers to register RPC interfaces of legitimate services before the actual services start, hijacking their connections 7:57-9:01
• The presenter developed RPC Recon to find vulnerable interfaces and RPC Racer to exploit them, forcing authentication from machine accounts 11:14
• By targeting the storage service, the attack forces the delivery optimization service (running as protected process) to authenticate against an attacker-controlled server 17:22-23:18
• While Microsoft patched the specific storage service vulnerability, many other RPC interfaces remain potentially vulnerable to similar attacks 31:34-34:18

The vulnerability demonstrates a fundamental issue in the Windows RPC protocol's security model, where the identity of servers registering interfaces is not properly verified, opening the door to various privilege escalation and persistence techniques 34:50-35:22.

Sources:

  • 4:38-5:11 Explanation of RPC protocol and endpoint mapper functionality
  • 7:57-9:01 Discovery and demonstration of EPM poisoning vulnerability

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello everyone. My name is Ron Benitra and I'm very excited to be here today and give you my talk. You snooze, you lose. RPC racer winning RPC endpoints against services. This year, this is the fourth year in a row I'm speaking here at Defcon. [Applause] I'll introduce myself first. I'm a security researcher at Safebridge where I do vulnerability research. I also like playing music and going to concerts. This is our agenda for today. At the beginning, I'll explain some basic terms regarding RBC. Then I'll expose some serious flaws in this very widely used protocol. I'll take you step by step showing how I manipulated a core component of RPC and masqueraded as a legitimate built-in service to force a protected process to authenticate against an arbitrary server and disclosing the NLM hash o…