Port 135 is primarily used by the RPC protocol, which enables communication between Windows services and applications running on different computers. It’s also vulnerable to DoS attacks, and in the past, has suffered a large-scale attack from an effective computer worm. In this article, you can learn some general information about this port, and basic tips on how to prevent it from becoming a security threat.
How RPC Works and Why It Uses Port 135
RPC (remote procedure calls) allow programmers to connect Windows apps and services on remote computers, without having to implement networking features. Any calls to the remote app are instead made to a local “stub” procedure, which then uses the RPC libraries to send the call over the network. Everything but the initial call happens in the background.
Endpoint Mapper, a component of RPC, uses port 135 to start connections and coordinate port use. Both for security and efficiency, apps tend to use separate TCP ports. An RPC server or a client usually has port 135 open. The remote machine uses the opened port to send a connection request to the Endpoint Mapper, and receives port numbers that will be used for the connection. The ports used for RPC, except for 135 or a different agreed-upon port, are always dynamically chosen, and not specified by the user.
RPC libraries are included with Windows, so it’s a commonly used communication method. In fact, it’s used in Active Directory, which is a large-scale administration tool for Windows computers. This makes it all the more necessary to know about the potential threats to port 135, or other fixed RPC ports.
Port 135 Exploits
Since RPC and port 135 in particular are a potential point of access to a computer’s system services, they have been the target of numerous attacks. One of the most well-known attacks targeting RPC is the Blaster worm. It used a vulnerability in the Endpoint Mapper to infect over 400 thousand machines before being patched out.
Nowadays, the port is mainly used for DoS attacks, with a port 135 vulnerability being discovered as recently as 2025. While not nearly as threatening as a worm, this can still disrupt a network of Windows computers, and cause financial damage to a business.
Best Practices
Both Microsoft and third-party cybersecurity providers recommend not to keep any unneeded ports, especially RPC port 135, open to the Internet. RPC is only intended to be used on trusted networks.
It’s also vital to use updated Windows versions, even on machines that are only exposed to a local network. For example, the Blaster has spread much faster once it got past an external server and into a trusted network. This could also be the case for future exploits.
If RPC communication over the Internet is needed, it’s best not to open port 135, but rather, to use an alternative. A VPN connection to a trusted network or an RPC-over-HTTP connection will allow for higher security without denying you the use of RPC.