PT-2026-35367 · Nozomi Networks · Arc
CVE-2026-33921
·
Published
2026-04-27
·
Updated
2026-08-11
CVSS v3.1
5.2
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows RPC Runtime versions Windows 10, 11, and Server 2016 through 2025
Description
A critical issue exists in the Windows Remote Procedure Call (RPC) Runtime within the
rpcrt4.dll library, specifically in the NdrComplexTypeBufferSize() function. The flaw is caused by an integer underflow in the memory allocation logic for complex data types when the RPC runtime receives a request where the element count is logically inconsistent with the provided offset. This allows an unauthenticated attacker to send specially crafted RPC requests to the RPC mapper (TCP port 135) or SMB (TCP port 445), leading to a heap-based buffer overflow. By overwriting function pointers in the RPC service heap, an attacker can achieve remote code execution with SYSTEM privileges. This issue is currently being exploited by botnets in the APAC region for lateral movement and domain-wide compromise.Recommendations
For Windows 10, 11, and Server 2016 through 2025:
- Block TCP ports 135 and 445 at the perimeter firewall for all inbound traffic from untrusted networks.
- Use host-based firewalls to restrict RPC traffic between internal workstations.
- Use the RPC Filter feature to restrict accessible interfaces over the network on critical servers.
- Enable SMB signing and encryption to increase the difficulty of session injection.
- Monitor event logs for Event ID 1000 involving
rpcrt4.dlland tracksvchost.exefor unauthorized child process spawns.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arc