Impact
The vulnerability is a use‑after‑free flaw in the Windows Reliable Multicast Transport (RMCAST) driver that allows an unauthenticated attacker to execute code over the network. When the driver processes a crafted RMCAST packet, it accesses memory that has already been freed, enabling the attacker to run arbitrary code with the privilege level of the driver. This flaw is classified as CWE‑416, which describes the use of freed memory after it has been released.
Affected Systems
The flaw affects numerous Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their Server Core variants. All 32‑bit, 64‑bit, and ARM64 builds are impacted, as listed in the provided CPEs.
Risk and Exploitability
The CVSS score of 8.1 indicates a high‑severity vulnerability that can lead to full system compromise. EPSS is not available, so the current likelihood of exploitation is uncertain, and the vulnerability is not yet listed in the CISA KEV catalog. Based on the description, the attacker can exploit the flaw remotely by sending malicious RMCAST traffic from an external network, meaning no local privileges or user interaction are required. The exploitation window exists on any system where RMCAST is enabled and processes network traffic.
OpenCVE Enrichment