cbcvebase.
CVE-2025-21307
published 2025-01-14

CVE-2025-21307: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.87%
77.0th percentile
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2089010.0.10240.20890
microsoftwindows_10_1607< 10.0.14393.769910.0.14393.7699
microsoftwindows_10_1809< 10.0.17763.677510.0.17763.6775
microsoftwindows_10_21h2< 10.0.19044.537110.0.19044.5371
microsoftwindows_10_22h2< 10.0.19045.537110.0.19045.5371
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2089010.0.10240.20890
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.769910.0.14393.7699
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.677510.0.17763.6775
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.537110.0.19044.5371
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.537110.0.19045.5371
microsoftwindows_11_22h2< 10.0.22621.475110.0.22621.4751
microsoftwindows_11_23h2< 10.0.22631.475110.0.22631.4751
microsoftwindows_11_24h2< 10.0.26100.289410.0.26100.2894
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.475110.0.22621.4751
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.475110.0.22631.4751
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.475110.0.22631.4751
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.289410.0.26100.2894
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.275206.1.7601.27520
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.230706.0.6003.23070
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.252736.2.9200.25273
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.223716.3.9600.22371
microsoftwindows_server_2016< 10.0.14393.769910.0.14393.7699
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.769910.0.14393.7699

Detection & IOCsextracted from sources · hover to see the quote

processRMCAST (Reliable Multicast Transport Driver)
  • Detect exploitation attempts by monitoring for specially crafted packets sent to Windows PGM open sockets from unauthenticated sources.
  • Identify exploitable systems by checking for programs actively listening on PGM ports — exploitation is only possible when a receiver is actively listening.
  • Alert on inbound PGM traffic from untrusted/external networks, particularly to systems running MSMQ or other PGM receivers, as PGM lacks authentication.
  • Successful exploitation requires a program that actively listens to a PGM port — enumerate hosts with PGM listeners as high-priority targets.
  • ·Exploitation is conditional — the vulnerability is NOT exploitable unless a program is actively listening on a PGM port. Prioritize detection and patching only for systems with active PGM receivers.
  • ·No public exploit or active exploitation confirmed as of the advisory date — treat as exploitation-less-likely but high-severity due to CVSS 9.8 and unauthenticated attack vector.
  • ·PGM protocol has no built-in authentication, making network-level controls (firewall blocking PGM ports) the primary compensating control when patching is delayed.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.