Impact
The vulnerability is a heap-based buffer overflow in the Windows Reliable Multicast Transport Driver (RMCAST) that allows an unauthorized attacker to execute arbitrary code on a target system. This flaw is a classic heap corruption issue (CWE‑122) with an associated integer overflow or wraparound weakness (CWE‑190). If successfully exploited, an attacker could run any code with the privileges of the RMCAST driver, potentially taking full control of the affected machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity threat. EPSS information is unavailable, but the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed public exploit yet. Based on the description, the likely attack vector is an attacker on an adjacent network able to send malicious traffic to the RMCAST driver. Exploitation would require network proximity and the presence of the vulnerable RMCAST service, but once triggered it allows remote code execution.
OpenCVE Enrichment