Junglewise Threat Intelligence

CVE-2026-54995: Microsoft Windows RMCAST use after free remote code execution

CVE-2026-54995 · Severity: high · CVSS 8.1 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A vulnerability exists in the Windows Reliable Multicast Transport Driver, a component used for efficient data transmission to multiple recipients simultaneously. An attacker could exploit this flaw to remotely execute malicious code on a target system without any user interaction. This could lead to a complete system takeover, unauthorized data access, or significant operational disruption.

Technical details

A use-after-free (CWE-416) vulnerability exists in the Reliable Multicast Transport Driver (RMCAST) of various Microsoft Windows and Windows Server versions. The flaw is triggered when the driver incorrectly manages memory objects during multicast transport operations. An unauthenticated attacker can exploit this over the network, though the attack complexity is rated as high, likely requiring specific timing or network conditions to successfully trigger the memory corruption. Successful exploitation allows for remote code execution (RCE) with elevated privileges. Microsoft has released security updates to address this issue across affected platforms.

Affected products

  • Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 Versions 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All editions

Timeline

  • 2026-07-14: disclosed: Initial disclosure by Microsoft and NVD publication.
  • 2026-07-14: patched: Security updates made available via Microsoft MSRC.

References

Related threats