
Researchers Uncover Windows EPM Exploit Chain for Domain Privilege Escalation
Researchers revealed a patched Windows RPC vulnerability (CVE-2025-49760) that allows attackers to perform EPM poisoning, impersonate services, manipulate RPC clients, and escalate privileges, highlighting the importance of monitoring RPC calls and verifying server identities to prevent exploitation.