PT-2026-35367 · Nozomi Networks · Arc

CVE-2026-33921

·

Published

2026-04-27

·

Updated

2026-08-11

CVSS v3.1

5.2

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows RPC Runtime versions Windows 10, 11, and Server 2016 through 2025
Description A critical issue exists in the Windows Remote Procedure Call (RPC) Runtime within the rpcrt4.dll library, specifically in the NdrComplexTypeBufferSize() function. The flaw is caused by an integer underflow in the memory allocation logic for complex data types when the RPC runtime receives a request where the element count is logically inconsistent with the provided offset. This allows an unauthenticated attacker to send specially crafted RPC requests to the RPC mapper (TCP port 135) or SMB (TCP port 445), leading to a heap-based buffer overflow. By overwriting function pointers in the RPC service heap, an attacker can achieve remote code execution with SYSTEM privileges. This issue is currently being exploited by botnets in the APAC region for lateral movement and domain-wide compromise.
Recommendations For Windows 10, 11, and Server 2016 through 2025:
  • Block TCP ports 135 and 445 at the perimeter firewall for all inbound traffic from untrusted networks.
  • Use host-based firewalls to restrict RPC traffic between internal workstations.
  • Use the RPC Filter feature to restrict accessible interfaces over the network on critical servers.
  • Enable SMB signing and encryption to increase the difficulty of session injection.
  • Monitor event logs for Event ID 1000 involving rpcrt4.dll and track svchost.exe for unauthorized child process spawns.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33921

Affected Products

Arc