ZeroHour

CVE-2026-78450

mass

Use-After-Free RCE in Microsoft Windows Reliable Multicast Transport Driver (RMCAST)

CVSS 3.1
8.1 high
EPSS
<1%p42
Published
()
Modified
AI analysis

CVE-2026-78450 is a use-after-free (CWE-416) in Microsoft's Reliable Multicast Transport Driver (RMCAST), the Windows networking component that handles reliable multicast transport traffic. An unauthenticated attacker can trigger the flaw by sending crafted network packets to a host running the affected driver; the high-attack-complexity rating (AV:N/AC:H) indicates exploitation depends on atypical conditions rather than a trivially reproducible request. Successful exploitation results in remote code execution on the target system. Any Windows system with the RMCAST driver loaded and reachable over the network is potentially affected; the reviewed data does not list specific Windows version ranges, and fixes were delivered in Microsoft's September 2026 Patch Tuesday. No public proof-of-concept or in-the-wild exploitation is currently known, and EPSS assigns only about a 0.5% probability of exploitation in the next 30 days.

What to do: Apply Microsoft's September 2026 Patch Tuesday security updates to all Windows systems, prioritizing servers where the reliable multicast (PGM) feature or Message Queuing is enabled or reachable from the network. Check which hosts load the RMCAST driver and restrict inbound multicast/PGM network access as an interim mitigation. With no known exploitation or public PoC, this is a routine patch-cycle item rather than an emergency, but patch promptly in case public details emerge.

Affected
Microsoft Windows Reliable Multicast Transport Driver (RMCAST)
Estimated exposure
masslikely >1,000,000 hosts carry the driver (Windows installed base is on the order of 1.4 billion devices), but the subset with the multicast feature… — RMCAST is an inbox Windows networking driver typically used with the optional reliable multicast/Message Queuing feature, so most Windows desktops and servers ship it while genuinely reachable deployments are a smaller subset, based on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.