ZeroHour

CVE-2026-69530

large

Use-After-Free RCE in Microsoft Windows Reliable Multicast Transport (RMCAST) Driver

CVSS 3.1
8.1 high
EPSS
<1%p44
Published
()
Modified
AI analysis

CVE-2026-69530 is a use-after-free memory-corruption flaw (CWE-416) in Microsoft's Reliable Multicast Transport Driver (RMCAST), the Windows networking component associated with the optional Message Queuing (MSMQ) feature. An unauthenticated attacker can reach the flaw over the network by sending traffic that leads the driver to use memory after it has been freed, though the High attack-complexity rating indicates exploitation depends on favorable runtime conditions rather than a simple request. A successful attack yields remote code execution on the affected host, with CVSS rating the impact high across confidentiality, integrity, and availability. Only systems where the RMCAST/MSMQ capability is installed and enabled are exposed, and the flaw was addressed in Microsoft's September 2026 Patch Tuesday release. There is currently no known exploitation, no public proof-of-concept, and no CISA KEV listing, with EPSS estimating roughly a 0.6% chance of exploitation in the next 30 days.

What to do: Apply Microsoft's September 2026 security updates as soon as practical. Inventory Windows hosts — especially servers reachable from untrusted networks — for the Message Queuing (MSMQ)/Reliable Multicast Transport feature and disable it where it is not required, since exposure requires the component to be installed and enabled. Given the High attack complexity, the absence of a public PoC, and no known exploitation, there is no indication of urgent in-the-wild risk, but patching should not be deferred.

Affected
Microsoft Windows Reliable Multicast Transport Driver (RMCAST) — Message Queuing (MSMQ) component
Estimated exposure
largeon the order of 100,000–1,000,000 Windows hosts with MSMQ/RMCAST installed (rough estimate; no public install-base counts provided) — RMCAST is delivered only through the optional, legacy Message Queuing (MSMQ) Windows feature rather than a default installation, so this estimate assumes a low single-digit percentage of the very large global enterprise Windows Server…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.