Executive brief
A security vulnerability exists in the Microsoft Windows Reliable Multicast Transport Driver, a component used for efficient data transmission to multiple recipients on a network. An attacker located on the same local network could exploit this flaw to take control of affected systems without needing any user interaction or login credentials. This could lead to a complete compromise of the system, unauthorized data access, or service disruptions.
Technical details
An integer underflow (CWE-191) exists in the Reliable Multicast Transport Driver (RMCAST) of Microsoft Windows. The vulnerability is triggered when the driver processes specially crafted multicast traffic, leading to a wrap or wraparound condition. An unauthenticated attacker on the same local network or subnet (adjacent) can exploit this to achieve remote code execution with kernel-level privileges. No user interaction is required for successful exploitation. Microsoft has released security updates to address this issue across affected Windows 10, Windows 11, and Windows Server 2012 versions.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All editions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory