CVE-2025-21307
published 2025-01-14CVE-2025-21307: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.87%
77.0th percentile
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20890 | 10.0.10240.20890 |
| microsoft | windows_10_1607 | < 10.0.14393.7699 | 10.0.14393.7699 |
| microsoft | windows_10_1809 | < 10.0.17763.6775 | 10.0.17763.6775 |
| microsoft | windows_10_21h2 | < 10.0.19044.5371 | 10.0.19044.5371 |
| microsoft | windows_10_22h2 | < 10.0.19045.5371 | 10.0.19045.5371 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20890 | 10.0.10240.20890 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.7699 | 10.0.14393.7699 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.6775 | 10.0.17763.6775 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.5371 | 10.0.19044.5371 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.5371 | 10.0.19045.5371 |
| microsoft | windows_11_22h2 | < 10.0.22621.4751 | 10.0.22621.4751 |
| microsoft | windows_11_23h2 | < 10.0.22631.4751 | 10.0.22631.4751 |
| microsoft | windows_11_24h2 | < 10.0.26100.2894 | 10.0.26100.2894 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.4751 | 10.0.22621.4751 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.4751 | 10.0.22631.4751 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.4751 | 10.0.22631.4751 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.2894 | 10.0.26100.2894 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27520 | 6.1.7601.27520 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.23070 | 6.0.6003.23070 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25273 | 6.2.9200.25273 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22371 | 6.3.9600.22371 |
| microsoft | windows_server_2016 | < 10.0.14393.7699 | 10.0.14393.7699 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.7699 | 10.0.14393.7699 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring for specially crafted packets sent to Windows PGM open sockets from unauthenticated sources. ↗
- →Identify exploitable systems by checking for programs actively listening on PGM ports — exploitation is only possible when a receiver is actively listening. ↗
- →Alert on inbound PGM traffic from untrusted/external networks, particularly to systems running MSMQ or other PGM receivers, as PGM lacks authentication. ↗
- →Successful exploitation requires a program that actively listens to a PGM port — enumerate hosts with PGM listeners as high-priority targets. ↗
- ·Exploitation is conditional — the vulnerability is NOT exploitable unless a program is actively listening on a PGM port. Prioritize detection and patching only for systems with active PGM receivers. ↗
- ·No public exploit or active exploitation confirmed as of the advisory date — treat as exploitation-less-likely but high-severity due to CVSS 9.8 and unauthenticated attack vector. ↗
- ·PGM protocol has no built-in authentication, making network-level controls (firewall blocking PGM ports) the primary compensating control when patching is delayed. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
vendor_msrc·2025-01-14·CVSS 9.8
CVE-2025-21307 [CRITICAL] CWE-416 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An unauthenticated attacker could exploit the vulnerability by sending specially crafted packets to a Windows Pragmatic General Multicast (PGM) open socket on the server, without any interaction from the user.
Reliable Multicast Transport Driver (RMCAST): Reliable Multicast Transport Driver (RMCAST)
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5050008
Reference: https://support.microsoft.com/help/5050008
Reference: https://catalog.upda
GHSA
GHSA-j9w9-6jj7-c2px: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
ghsa_unreviewed·2025-01-14
CVE-2025-21307 [CRITICAL] CWE-416 GHSA-j9w9-6jj7-c2px: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
Qualys
Mitigate CVE-2025-21307 Risk Before the Weekend | Qualys
blogs_qualys·2025-01-17·CVSS 9.8
CVE-2025-21307 [CRITICAL] Mitigate CVE-2025-21307 Risk Before the Weekend | Qualys
#### Table of Contents
- Understanding CVE-2025-21307: What You Need to Know
- How to Deploy a Patch for CVE-2025-21307 Before the Weekend
- Mitigating risk of CVE-2025-21307 When Patching is Not Possible: Immediate Actions
Microsoft’s January 2025 Patch Tuesday release addresses a critical vulnerability—CVE-2025-21307—in the Windows Reliable Multicast Transport Driver (RMCAST). With a CVSS score of 9.8, this vulnerability poses a severe threat and is highly susceptible to exploitation.
## Understanding CVE-2025-21307: What You Need to Know
RMCAST is a kernel-level Windows component responsible for implementing reliable multicast communication. It specifically supports the Pragmatic General Multicast (PGM) protocol, which enables applications to send data packets simultaneously to mult
Qualys
How to Mitigate risk of CVE-2025-21307 Before the Weekend Without a Patch
blogs_qualys·2025-01-17·CVSS 9.8
CVE-2025-21307 [CRITICAL] How to Mitigate risk of CVE-2025-21307 Before the Weekend Without a Patch
## Table of Contents
Understanding CVE-2025-21307: What You Need to Know
How to Deploy a Patch for CVE-2025-21307 Before the Weekend
Mitigating risk of CVE-2025-21307 When Patching is Not Possible: Immediate Actions
Microsoft’s January 2025 Patch Tuesday release addresses a critical vulnerability— CVE-2025-21307 —in the Windows Reliable Multicast Transport Driver (RMCAST). With a CVSS score of 9.8, this vulnerability poses a severe threat and is highly susceptible to exploitation.
## Understanding CVE-2025-21307: What You Need to Know
RMCAST is a kernel-level Windows component responsible for implementing reliable multicast communication. It specifically supports the Pragmatic General Multicast (PGM) protocol, which enables applications to send data packets simultaneously to multiple
Bleepingcomputer
Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws
blogs_bleepingcomputer·2025-01-14·CVSS 7.8
[HIGH] Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws
## Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws
## Lawrence Abrams
40 Elevation of Privilege Vulnerabilities
14 Security Feature Bypass Vulnerabilities
58 Remote Code Execution Vulnerabilities
24 Information Disclosure Vulnerabilities
20 Denial of Service Vulnerabilities
5 Spoofing Vulnerabilities
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5050009 & KB5050021 cumulative updates and the Windows 10 KB5048652 cumulative update.
## Three actively exploited zero-day disclosed
This month's Patch Tuesday fixes three actively exploited and five publicly exposed zero-day vulnerabilities.
Microsoft classifies a zero-day flaw as one that is publicly disclosed or actively exploited while no offi
Qualys
Microsoft and Adobe Patch Tuesday, January 2025 Security Update Review
blogs_qualys·2025-01-14
Microsoft and Adobe Patch Tuesday, January 2025 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for January 2025
Adobe Patches for January 2025
Zero-day Vulnerabilities Patched in January Patch Tuesday Edition
Critical Severity Vulnerabilities Patched in January Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
Happy New Year! As the calendar turns to January 2025, Microsoft’s first Patch Tuesday of 2025 has arrived. From zero-days to critical vulnerabilities, here’s what deserves your attention. Here’s a breakdown of what’s been patched.
## Microsoft Patch Tu
Talos
Microsoft Patch Tuesday for January 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-01-14·CVSS 8.1
CVE-2025-21309 [HIGH] Microsoft Patch Tuesday for January 2025 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for January 2025 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for January of 2025 which includes 159 vulnerabilities, including 12 that Microsoft marked as “critical.” The remaining vulnerabilities listed are classified as “important.”
One notable critically rated vulnerability that has been patched this month is CVE-2025-21309 , which is a remote code execution vulnerability affecting Windows Remote Desktop Services. Exploitation of this vulnerability could lead to arbitrary code execution on systems where the Remote Desktop Gateway role has been enabled. This vulnerability has been assigned a CVSS 3.1 score of 8.1 and is considered “more likely to be exploited” by Microsoft.
Another notable remote code execut
Qualys
Microsoft and Adobe Patch Tuesday, January 2025 Security Update Review | Qualys
blogs_qualys·2025-01-14
Microsoft and Adobe Patch Tuesday, January 2025 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for January 2025
- Adobe Patches for January 2025
- Zero-day Vulnerabilities Patched in January Patch Tuesday Edition
- Critical Severity Vulnerabilities Patched in January Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
Happy New Year! As the calendar turns to January 2025, Microsoft’s first Patch Tuesday of 2025 has arrived. From zero-days to critical vulnerabilities, here’s what deserves your attention. Here’s a breakdown of what’s been patched.
## Micro
Talos
Microsoft Patch Tuesday for January 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-01-14·CVSS 8.1
CVE-2025-21309 [HIGH] Microsoft Patch Tuesday for January 2025 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for January of 2025 which includes 159 vulnerabilities, including 12 that Microsoft marked as “critical.” The remaining vulnerabilities listed are classified as “important.”
One notable critically rated vulnerability that has been patched this month is CVE-2025-21309, which is a remote code execution vulnerability affecting Windows Remote Desktop Services. Exploitation of this vulnerability could lead to arbitrary code execution on systems where the Remote Desktop Gateway role has been enabled. This vulnerability has been assigned a CVSS 3.1 score of 8.1 and is considered “more likely to be exploited” by Microsoft.
Another notable remote code execution vulnerability in Window Object Linking and Embedding (OLE) was also patched this month
Crowdstrike
January 2025 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] January 2025 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
2025-01-14
Published