Junglewise Threat Intelligence

CVE-2026-78449: Microsoft Reliable Multicast Transport Driver use-after-free remote code execution

CVE-2026-78449 · Severity: high · CVSS 8.1 · Published 2026-09-08

Executive brief

Reliable Multicast Transport Driver (RMCAST) is a Windows network transport component used for efficient group communication. A use-after-free vulnerability allows an attacker to execute arbitrary code remotely over the network without authentication, potentially compromising system integrity and enabling malware deployment or lateral movement.

Technical details

A use-after-free vulnerability in the Reliable Multicast Transport Driver (RMCAST) permits remote code execution over the network. The vulnerability stems from improper memory management in the RMCAST kernel component when handling multicast transport protocol messages. An unauthenticated attacker on a network can send crafted multicast packets to trigger the use-after-free condition and execute arbitrary code in kernel context. No user interaction is required; the attack is triggered purely by network traffic. Patches or workarounds should be available from Microsoft Security Response Center.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats