ZeroHour

CVE-2026-78449

large

Use-after-free RCE in Microsoft Windows Reliable Multicast Transport Driver (RMCAST)

CVSS 3.1
8.1 high
EPSS
<1%p42
Published
()
Modified
AI analysis

CVE-2026-78449 is a use-after-free flaw (CWE-416) in Microsoft's Reliable Multicast Transport Driver (RMCAST, rmcast.sys), the Windows driver that implements the PGM reliable multicast transport used by features such as Message Queuing (MSMQ). An unauthorized remote attacker could trigger it by sending crafted network traffic that causes the driver to access freed memory, although the high attack complexity (CVSS AC:H) means exploitation depends on favorable timing or state conditions. Successful exploitation would allow arbitrary code execution in the context of the driver, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.1, High). Only systems running the affected RMCAST driver - typically Windows hosts where the optional Reliable Multicast Protocol/MSMQ multicast capability is installed, enabled, and network-reachable - are exposed; the specific affected Windows versions are enumerated in Microsoft's September 2026 Patch Tuesday release. As of now there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it a low 0.5% probability of exploitation within 30 days, so exploitation has not yet been observed.

What to do: Apply Microsoft's September 2026 Patch Tuesday updates promptly, prioritizing any servers or workstations with Message Queuing (MSMQ) or the optional Reliable Multicast Protocol (PGM) feature enabled, and confirm the updated rmcast.sys driver is loaded after reboot. Until patched, consider disabling the Reliable Multicast Protocol feature or restricting network access to trusted sources on affected hosts. Check Microsoft's advisory for the definitive list of affected Windows versions and any exploitability updates.

Affected
Microsoft Windows - Reliable Multicast Transport Driver (RMCAST / rmcast.sys)
Estimated exposure
large~100k-1M Windows hosts (order-of-magnitude estimate; only systems with the optional PGM/MSMQ reliable multicast transport enabled and reachable) — Estimated from deployment patterns rather than scan data: Windows runs on well over a billion devices, but the RMCAST/PGM driver is only loaded where the optional Reliable Multicast Protocol feature (commonly used with Message Queuing) is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.