{"schema_version":"1.0","report_url":"https://aretiq.ai/research/vul260702-cve-2026-54995-microsoft-windows-reliable-multicast-transport-driver-integer-underflow/","date":"2026-07-02","last_modified":"2026-07-02","cve":"CVE-2026-54995","title":"CVE-2026-54995 — Microsoft Windows Reliable Multicast Transport Driver Integer Underflow","vulnerability_name":"Microsoft Windows Reliable Multicast Transport Driver Integer Underflow","vendor":"Microsoft","product":"Windows","component":"Reliable Multicast Transport Driver","binary":"rmcast.sys","impact":"RCE","cwe":["CWE-191","CWE-416","CWE-787"],"severity":{"cvss_v4_score":7.2,"cvss_v4_vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U"},"attack_vector":"Network","patch_kb":"KB5099536","poc_verified":false,"poc_download":"https://aretiq.ai/downloads/","tags":["cve-2026-54995","rmcast","pgm","multicast","fec","rce","kernel"],"summary":"CVE-2026-54995 — Microsoft Windows Reliable Multicast Transport Driver Integer Underflow 1. Overview A vulnerability exists in the Windows Reliable Multicast Transport Driver (rmcast.sys) that implements the Pragmatic General Multicast (PGM) protocol. When processing incoming ODATA packets for a Forward Error Correction (FEC) group, the driver’s PgmHandleNewData function can decrement a parity packet counter past zero, causing an unsigned byte to underflow from 0 to 255. This corrupted counter subsequently causes out-of-bounds memory access when the driver attempts FEC decoding with an impossibly large parity count. An unauthenticated remote attacker can send specially crafted PGM multicast packets to a system running a PGM receiver application, potentially achieving kernel-level code execution. Microsoft addressed this vulnerability in the July 2026 security update.\n"}