Impact
The vulnerability is an use‑after‑free flaw in the Windows Reliable Multicast Transport Driver (RMCAST) that permits an attacker with no authentication to execute arbitrary code on the target machine. This flaw falls under CWE‑416 and enables remote code execution, which can compromise confidentiality, integrity and availability of the affected system.
Affected Systems
Affected systems include Microsoft Windows 10 Version 1809, Microsoft Windows Server 2019 (both conventional and Server Core installations), Microsoft Windows Server 2022, and Microsoft Windows Server 2025 (both conventional and Server Core). All these products contain the vulnerable RMCAST driver that can be exploited.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity level, and the vulnerability is listed as not in the CISA KEV catalog with no EPSS data available. The description explicitly states that an unauthorized attacker can execute code over a network, implying a remote attack vector that requires no prior credentials. The exploit would involve sending crafted multicast traffic that triggers the use‑after‑free in the driver, leading to code execution on the target system.
OpenCVE Enrichment