A new vulnerability in Windows RPC, known as CVE-2022-26809 , has raised security concerns due to the potential for widespread cyberattacks once an exploit is deployed. Microsoft is urging all organizations to apply security updates as soon as possible.
See also: Facebook News Feed bug introduces misinformation into users' feeds

The company has patched the vulnerability as part of the April 2022 Patch Tuesday updates and has rated it as “Critical,” as it allows unauthorized remote code execution via a bug in Microsoft’s communications protocol, Remote Procedure Call (RPC).
If a malicious user exploits the vulnerability, any commands will be executed at the same privilege level as the RPC server, which in many cases has elevated or SYSTEM-level privileges, providing full administrator access to the exploited device
Microsoft's Remote Procedure Call Protocol (Windows RPC) is a communication protocol that allows processes to communicate with each other, even if those programs are running on another device.
See also: CISA: Fix the Sophos firewall bug
After Microsoft released security updates, researchers quickly saw the potential for this flaw to be exploited in widespread attacks, similar to the 2003 Blaster worm and the 2017 Wannacry attacks using the Eternal Blue vulnerability.

Researchers have already begun analyzing and publishing technical details about the vulnerability, which other researchers and threat actors will use to combine into a functional exploit, such as a buffer.
The good news is that it probably requires a specific RPC configuration to be vulnerable, but this is still under analysis.
As this vulnerability is ideal for lateral spread across a network, we will almost certainly see it used by ransomware in the future.
See also: Western Digital: Bug allowed rooting on My Cloud NAS devices
While there's no need to panic about this vulnerability just yet, administrators should make patching these devices a priority, as an exploit could be released at any time.
Once an exploit is released, it usually only takes a short time for threat actors to use it in attacks.
