Use-After-Free RCE in Microsoft Windows Reliable Multicast Transport Driver (RMCAST)
AI analysis
CVE-2026-78450 is a use-after-free (CWE-416) in Microsoft's Reliable Multicast Transport Driver (RMCAST), the Windows networking component that handles reliable multicast transport traffic. An unauthenticated attacker can trigger the flaw by sending crafted network packets to a host running the affected driver; the high-attack-complexity rating (AV:N/AC:H) indicates exploitation depends on atypical conditions rather than a trivially reproducible request. Successful exploitation results in remote code execution on the target system. Any Windows system with the RMCAST driver loaded and reachable over the network is potentially affected; the reviewed data does not list specific Windows version ranges, and fixes were delivered in Microsoft's September 2026 Patch Tuesday. No public proof-of-concept or in-the-wild exploitation is currently known, and EPSS assigns only about a 0.5% probability of exploitation in the next 30 days.
What to do: Apply Microsoft's September 2026 Patch Tuesday security updates to all Windows systems, prioritizing servers where the reliable multicast (PGM) feature or Message Queuing is enabled or reachable from the network. Check which hosts load the RMCAST driver and restrict inbound multicast/PGM network access as an interim mitigation. With no known exploitation or public PoC, this is a routine patch-cycle item rather than an emergency, but patch promptly in case public details emerge.
Affected
| Microsoft Windows Reliable Multicast Transport Driver (RMCAST) | — |
Estimated exposure
masslikely >1,000,000 hosts carry the driver (Windows installed base is on the order of 1.4 billion devices), but the subset with the multicast feature… — RMCAST is an inbox Windows networking driver typically used with the optional reliable multicast/Message Queuing feature, so most Windows desktops and servers ship it while genuinely reachable deployments are a smaller subset, based on…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.