Impact
A use‑after‑free flaw in the Windows Reliable Multicast Transport Driver (RMCAST) (CWE‑416) allows an unauthorized attacker to execute arbitrary code on the affected system. The vulnerability occurs when RMCAST frees a memory buffer prematurely, enabling malicious packets to manipulate execution flow. Exploiting this flaw would compromise the confidentiality, integrity, and availability of the host by running code with the privileges of the RMCAST service.
Affected Systems
Affected systems include Microsoft Windows operating systems such as Windows 10 build 1607, 1809, 21H2, 22H2, Windows 11 build 24H2, 25H2, 26H1, as well as Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, 2025 and their Server Core variants.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, but the EPSS score of less than 1% shows a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based delivery of a malformed multicast packet that triggers the use‑after‑free. If an attacker has network access to a host running the vulnerable RMCAST driver, they could achieve remote code execution without requiring local privileges.
OpenCVE Enrichment