A recently patched security flaw in Microsoft’s Windows Remote Procedure Call (RPC) communication protocol has led cybersecurity researchers to report fresh findings that might be exploited by an attacker to carry out spoofing attacks and pose as a known server.
As a Windows Storage spoofing problem, the tech giant has identified the vulnerability as CVE-2025-49760 (CVSS score: 3.5). As part of its monthly Patch Tuesday release, it was resolved in July 2025. At this week’s DEF CON 33 security conference, SafeBreach researcher Ron Ben Yizhak provided details on the security flaw.
In an advisory published last month, the company stated that an authorized attacker can perform spoofing across a network by externally controlling the file name or path in Windows Storage read more about Researchers Detail Windows EPM Poisoning Exploit Chain Leading to Domain Privilege Escalation.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
