Junglewise Threat Intelligence

CVE-2026-78450: Microsoft RMCAST use-after-free remote code execution

CVE-2026-78450 · Severity: high · CVSS 8.1 · Published 2026-09-08

Executive brief

The Reliable Multicast Transport Driver (RMCAST) is a Windows kernel-mode driver used for multicast network communication. A use-after-free vulnerability allows an attacker on the network to execute arbitrary code with kernel privileges, potentially compromising the entire system and any data it contains.

Technical details

A use-after-free vulnerability exists in the RMCAST kernel driver, where memory is accessed after being deallocated. The vulnerability is reachable over the network without requiring user authentication or interaction. An attacker can exploit this to achieve remote code execution in kernel mode, gaining complete system control. A patch from Microsoft is expected to be available through Windows Update.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats