Description
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an use‑after‑free flaw in the Windows Reliable Multicast Transport Driver (RMCAST) that permits an attacker with no authentication to execute arbitrary code on the target machine. This flaw falls under CWE‑416 and enables remote code execution, which can compromise confidentiality, integrity and availability of the affected system.

Affected Systems

Affected systems include Microsoft Windows 10 Version 1809, Microsoft Windows Server 2019 (both conventional and Server Core installations), Microsoft Windows Server 2022, and Microsoft Windows Server 2025 (both conventional and Server Core). All these products contain the vulnerable RMCAST driver that can be exploited.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity level, and the vulnerability is listed as not in the CISA KEV catalog with no EPSS data available. The description explicitly states that an unauthorized attacker can execute code over a network, implying a remote attack vector that requires no prior credentials. The exploit would involve sending crafted multicast traffic that triggers the use‑after‑free in the driver, leading to code execution on the target system.

Generated by OpenCVE AI on September 8, 2026 at 21:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that fixes the RMCAST driver vulnerability (CVE-2026-69530) as soon as it becomes available.
  • If the patch is delayed, restrict or block inbound multicast traffic that could reach the RMCAST driver by configuring Windows Firewall or network segmentation to limit exposure to trusted peers only.
  • Consider disabling the RMCAST feature or reducing multicast usage on systems where it is not required, and monitor system logs for any anomalous RMCAST activity after remediation.

Generated by OpenCVE AI on September 8, 2026 at 21:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Title Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1809
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1809
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1809 Windows Server 2019 Windows Server 2019 (server Core Installation) Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:39:02.134Z

Reserved: 2026-08-03T21:12:04.476Z

Link: CVE-2026-69530

cve-icon Vulnrichment

Updated: 2026-09-08T18:36:25.734Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:19:20.883

Modified: 2026-09-09T04:18:58.287

Link: CVE-2026-69530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:45:17Z

Weaknesses