Description
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via Use after Free
Action: Apply Patch
AI Analysis

Impact

A use-after-free flaw exists in the Windows Reliable Multicast Transport Driver (RMCAST) that enables an attacker to execute arbitrary code on affected systems. The vulnerability is classified as CWE‑416 and allows exploitation without user interaction. Successful exploitation compromises the confidentiality, integrity, and availability of the target system by granting the attacker code execution privileges within the RMCAST context.

Affected Systems

The flaw affects several Microsoft products: Windows 10 Version 1809, Windows Server 2019 (both standard and Server Core installations), Windows Server 2022, and Windows Server 2025 (both standard and Server Core). These operating system releases incorporate the RMCAST component that is vulnerable.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. EPSS evidence is not available, so the exploitation probability is currently unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploit at this time. Attackers would likely need network access to send malicious multicast traffic to trigger the use‑after‑free, and success would require the RMCAST process to be running. As no public workaround is documented, the risk remains high until a security update is applied.

Generated by OpenCVE AI on September 9, 2026 at 02:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that addresses CVE-2026-78450, which is documented in the Microsoft Security Release Guide.
  • If a patch is not yet available, block or restrict multicast traffic associated with RMCAST on the network or disable the RMCAST component via Group Policy or registry settings to prevent the flaw from being triggered.
  • Implement network segmentation or firewall rules that limit inbound multicast traffic to the affected hosts, thereby reducing the attack surface for this vulnerability.

Generated by OpenCVE AI on September 9, 2026 at 02:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2019 (server Core Installation)
Microsoft windows Server 2025 (server Core Installation)

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Title Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1809
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1809
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1809 Windows Server 2019 Windows Server 2019 (server Core Installation) Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:09.582Z

Reserved: 2026-08-24T16:21:50.286Z

Link: CVE-2026-78450

cve-icon Vulnrichment

Updated: 2026-09-09T09:53:34.058Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:43.340

Modified: 2026-09-16T20:30:36.543

Link: CVE-2026-78450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:48:52Z

Weaknesses