MS-RPC is Microsoft's implementation of the Remote Procedure Calls protocol. The protocol is extremely widespread, and serves as the basis for nearly all Windows services on both managed and unmanaged networks. As a core component of Windows, it has been around for a long while, and was shown to contain multitudes of security issues. In this talk, we will focus on MS-RPC’s integration with Windows authentication, specifically NTLM. Even nowadays, NTLM relay attacks are a plague on Windows domains, despite the many security mechanisms implemented to combat them. We will discuss the nuances of RPC and NTLM authentication, the failpoints of their interaction and their potential impact. We will demonstrate everything by showcasing a new vulnerability we found in a core component of the Windows API, which handles remote interactions with the Windows Registry. The vulnerability allows attackers to downgrade the secure-by-default authentication to an insecure channel and relay it to a different service as they see fit, allowing full domain takeover. We show the full process of vulnerability discovery, the mechanisms involved and the process to create a working PoC.