CVE-2026-62816 — Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Executive Summary
Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
Overview
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems | 5120418 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5120418 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5120238 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5120238 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5120249 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5120249 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5120249 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5120249 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5120249 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5120249 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5120240 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5120240 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Critical Remote Code Execution 5101650 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Critical Remote Code Execution 5101650 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Critical Remote Code Execution 5101650 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Critical Remote Code Execution 5101650 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems | 5121000 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 11 version 26H1 for x64-based Systems | 5121000 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2012 | 5120386 (Monthly Rollup) |
Critical | Remote Code Execution | Yes |
| Windows Server 2012 (Server Core installation) | 5120386 (Monthly Rollup) |
Critical | Remote Code Execution | Yes |
| Windows Server 2012 R2 | 5120385 (Monthly Rollup) |
Critical | Remote Code Execution | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5120385 (Monthly Rollup) |
Critical | Remote Code Execution | Yes |
| Windows Server 2016 | 5120418 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2016 (Server Core installation) | 5120418 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2019 | 5120238 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2019 (Server Core installation) | 5120238 (Security Update) |
Critical | Remote Code Execution | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5120418 |
Security Update | Yes |
5120238 |
Security Update | Yes |
5120249 |
Security Update | Yes |
5120240 |
Security Update | Yes |
5121000 |
Security Update | Yes |
5120386 |
Monthly Rollup | Yes |
5120385 |
Monthly Rollup | Yes |
Patch Diff
Integer overflow (CWE-190) leading to a heap-based buffer overflow (CWE-122) in the Windows Reliable Multicast Transport Driver rmcast.sys (PGM - Pragmatic General Multicast), unauthenticated remote code execution over an adjacent network (Critical, AV:A, CVSS 8.8). PGM provides reliability via NAK-driven retransmission of repair data (RData). When PgmSendRData services a received NAK, it derives an index from the NAK (GetNextNakIndex -> local_a7) and combines it into local_a4, then computes the repair-data buffer offset as roughly (local_a4 - window_trail) * per_packet_stride. PRE: the NAK-derived index was attacker-influenced and the subtract/multiply were performed without adequate range validation, so a crafted NAK could wrap the arithmetic (CWE-190) and produce a miscalculated offset/length that was then used for the repair-data copy - an out-of-bounds heap write (CWE-122). Because RMCAST processes multicast packets without authentication over an adjacent network, the overwrite is an RCE primitive (Microsoft rates it Critical 8.8). Diff of rmcast.sys 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) shows PgmSendRData (with AdvanceWindow, SendNextPacket, DestroyEntry) reworked under CFR flag Feature_4002387257: the repair-data copy is converted from memmove to a length-bounded memcpy and the NAK-derived index local_a4 is range-validated before it drives the (local_a4 - trail) * stride offset multiply, closing the overflow. Stated at confirmed-changed level (the update is a substantial rework of the PGM send path; 3 code changes + 2 new helpers).
| Function | Address | Change | Note |
|---|---|---|---|
PgmSendRData |
code change |
code (NAK-index range validation + bounded copy, CFR-gated) | Pre: (local_a4 - trail) * stride offset computed from an attacker-influenced NAK-derived index without range validation, then used to copy repair data (memmove) - integer overflow -> OOB heap write. Post (Feature_4002387257): local_a4 range-validated before the offset multiply and the copy converted to a length-bounded memcpy. |
AdvanceWindow / SendNextPacket / DestroyEntry |
code change |
code (PGM send-window path reworked in same update) | Transmit-window advancement, next-packet send, and entry teardown reworked alongside PgmSendRData; AdvanceWindow return type and SendNextPacket signature changed. Two new helper functions added. |
Feature_4002387257 |
gate |
added (CFR gate) | Dominant CFR flag gating the validated PGM send path; the original unvalidated arithmetic still ships when the flag is disabled. |
Attack Path
A crafted PGM NAK overflows the repair-data offset arithmetic, overflowing the heap during RData retransmission
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.