Critical CVSS 8.8 EPSS 0.00401 🔬 Patch diffed 2026-08 archive

Executive Summary

Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

Overview

8.8
CVSS HIGH
Critical
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Remote Code Execution
Released Aug 11 2026
Last Updated Aug 11 2026
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.00401 — 0.33242 percentile
NVD CVSS 8.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Adjacent_network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 7.7

EPSS Score

0.00401
probability of exploitation in the next 30 days
0.33242 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

22 affected products
Product KB Article Severity Impact Restart Required
Windows 10 Version 1607 for 32-bit Systems 5120418 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 1607 for x64-based Systems 5120418 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 1809 for 32-bit Systems 5120238 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 1809 for x64-based Systems 5120238 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 21H2 for 32-bit Systems 5120249 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 21H2 for ARM64-based Systems 5120249 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 21H2 for x64-based Systems 5120249 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 22H2 for 32-bit Systems 5120249 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 22H2 for ARM64-based Systems 5120249 (Security Update) Critical Remote Code Execution Yes
Windows 10 Version 22H2 for x64-based Systems 5120249 (Security Update) Critical Remote Code Execution Yes
Windows 11 Version 23H2 for ARM64-based Systems 5120240 (Security Update) Critical Remote Code Execution Yes
Windows 11 Version 23H2 for x64-based Systems 5120240 (Security Update) Critical Remote Code Execution Yes
Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Critical Remote Code Execution 5101650 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Critical Remote Code Execution 5101650 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Critical Remote Code Execution 5101650 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Critical Remote Code Execution 5101650 Base: 8.8 Temporal: 7.7 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems 5121000 (Security Update) Critical Remote Code Execution Yes
Windows 11 version 26H1 for x64-based Systems 5121000 (Security Update) Critical Remote Code Execution Yes
Windows Server 2012 5120386 (Monthly Rollup) Critical Remote Code Execution Yes
Windows Server 2012 (Server Core installation) 5120386 (Monthly Rollup) Critical Remote Code Execution Yes
Windows Server 2012 R2 5120385 (Monthly Rollup) Critical Remote Code Execution Yes
Windows Server 2012 R2 (Server Core installation) 5120385 (Monthly Rollup) Critical Remote Code Execution Yes
Windows Server 2016 5120418 (Security Update) Critical Remote Code Execution Yes
Windows Server 2016 (Server Core installation) 5120418 (Security Update) Critical Remote Code Execution Yes
Windows Server 2019 5120238 (Security Update) Critical Remote Code Execution Yes
Windows Server 2019 (Server Core installation) 5120238 (Security Update) Critical Remote Code Execution Yes

Patches

7 patches
Article Type Restart
5120418 Security Update Yes
5120238 Security Update Yes
5120249 Security Update Yes
5120240 Security Update Yes
5121000 Security Update Yes
5120386 Monthly Rollup Yes
5120385 Monthly Rollup Yes

Patch Diff

ghidriff · rmcast.sys (KB5121003)

Integer overflow (CWE-190) leading to a heap-based buffer overflow (CWE-122) in the Windows Reliable Multicast Transport Driver rmcast.sys (PGM - Pragmatic General Multicast), unauthenticated remote code execution over an adjacent network (Critical, AV:A, CVSS 8.8). PGM provides reliability via NAK-driven retransmission of repair data (RData). When PgmSendRData services a received NAK, it derives an index from the NAK (GetNextNakIndex -> local_a7) and combines it into local_a4, then computes the repair-data buffer offset as roughly (local_a4 - window_trail) * per_packet_stride. PRE: the NAK-derived index was attacker-influenced and the subtract/multiply were performed without adequate range validation, so a crafted NAK could wrap the arithmetic (CWE-190) and produce a miscalculated offset/length that was then used for the repair-data copy - an out-of-bounds heap write (CWE-122). Because RMCAST processes multicast packets without authentication over an adjacent network, the overwrite is an RCE primitive (Microsoft rates it Critical 8.8). Diff of rmcast.sys 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) shows PgmSendRData (with AdvanceWindow, SendNextPacket, DestroyEntry) reworked under CFR flag Feature_4002387257: the repair-data copy is converted from memmove to a length-bounded memcpy and the NAK-derived index local_a4 is range-validated before it drives the (local_a4 - trail) * stride offset multiply, closing the overflow. Stated at confirmed-changed level (the update is a substantial rework of the PGM send path; 3 code changes + 2 new helpers).

Pre-patch version 10.0.26100.8972 Download
Post-patch version 10.0.26100.9168 Download
Function Address Change Note
PgmSendRData code change code (NAK-index range validation + bounded copy, CFR-gated) Pre: (local_a4 - trail) * stride offset computed from an attacker-influenced NAK-derived index without range validation, then used to copy repair data (memmove) - integer overflow -> OOB heap write. Post (Feature_4002387257): local_a4 range-validated before the offset multiply and the copy converted to a length-bounded memcpy.
AdvanceWindow / SendNextPacket / DestroyEntry code change code (PGM send-window path reworked in same update) Transmit-window advancement, next-packet send, and entry teardown reworked alongside PgmSendRData; AdvanceWindow return type and SendNextPacket signature changed. Two new helper functions added.
Feature_4002387257 gate added (CFR gate) Dominant CFR flag gating the validated PGM send path; the original unvalidated arithmetic still ships when the flag is disabled.
View full diff report View RCA report

Attack Path

A crafted PGM NAK overflows the repair-data offset arithmetic, overflowing the heap during RData retransmission

Attack path for CVE-2026-62816 A crafted PGM NAK overflows the repair-data offset arithmetic, overflowing the heap during RData retransmission 01 — ENTRY Attacker sends crafted PGM/RMCAST NAK traffic over an adjacent network rmcast!PgmSendRData services the NAK to retransmit repair data. AV:A / PR:N / UI:N (unauthenticated, adjacent network). 02 — CONTROLLED INPUT Controls the NAK-derived sequence index GetNextNakIndex yields an attacker-influenced index combined into local_a4, used to locate/size the repair data. 03 — MISSING CHECK (index - trail) * stride offset overflows (CWE-190) The unvalidated index drives the offset multiply to wrap, producing a miscalculated offset/length for the repair-data copy. 04 — IMPACT Out-of-bounds repair-data copy -> heap overflow -> RCE The repair-data memcpy writes past the heap buffer using the wrapped offset/length; unauthenticated, this is a Critical (8.8) remote code-execution primitive in the kernel driver.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Exploits & PoC

Detection Rules

Acknowledgments