Impact
A use-after-free flaw exists in the Windows Reliable Multicast Transport Driver (RMCAST) that enables an attacker to execute arbitrary code on affected systems. The vulnerability is classified as CWE‑416 and allows exploitation without user interaction. Successful exploitation compromises the confidentiality, integrity, and availability of the target system by granting the attacker code execution privileges within the RMCAST context.
Affected Systems
The flaw affects several Microsoft products: Windows 10 Version 1809, Windows Server 2019 (both standard and Server Core installations), Windows Server 2022, and Windows Server 2025 (both standard and Server Core). These operating system releases incorporate the RMCAST component that is vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. EPSS evidence is not available, so the exploitation probability is currently unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploit at this time. Attackers would likely need network access to send malicious multicast traffic to trigger the use‑after‑free, and success would require the RMCAST process to be running. As no public workaround is documented, the risk remains high until a security update is applied.
OpenCVE Enrichment