⚡ A critical vulnerability (CVE-2025-49760) in Windows' internal RPC framework allowed malicious act

in #hacknews28 days ago

media.jpg

⚡ A critical vulnerability (CVE-2025-49760) in Windows' internal RPC framework allowed malicious actors to impersonate legitimate system services, effectively executing man-in-the-middle attacks within the operating system.

What's even more alarming? Attackers could manipulate Windows Defender's identity to bypass security measures.

For a deeper dive into the EPM poisoning technique, check out the detailed analysis here: https://thehackernews.com/2025/08/researchers-detail-windows-epm.html