Impact
An integer underflow flaw (CWE‑191) in the Windows Reliable Multicast Transport Driver (RMCAST) allows a malformed multicast packet to corrupt a counter or size field, resulting in the driver executing arbitrary code. The impact is remote code execution on the target system; however, the exact privilege level is not stated in the description and is therefore inferred to be similar to the privileges of the RMCAST process, typically local system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2012 through 2025—including Server Core deployments—are affected.
Risk and Exploitability
The CVSS score of 8.8 flags high severity, while the EPSS score of less than 1% indicates a very low but non‑zero likelihood of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network proximity, requiring an attacker to send malicious multicast packets from the same local network or VLAN to trigger the flaw, which would grant remote code execution with the privileges of the RMCAST component.
OpenCVE Enrichment