CVE-2026-55013: Windows Remote Help Defense Spoofing Vulnerability
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
Other sources
Windows Remote Help Defense Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.2.1040.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must already be authorized on the affected Windows system and be able to act locally. The provided vector indicates low attack complexity and no user interaction requirement.
What is the likely impact?
The reported impact is spoofing. The supplied severity vector also rates confidentiality and integrity impact as high, while availability impact is listed as none.
Is this remotely exploitable?
No. The attack vector is local, so exploitation requires access to the affected system rather than network-only access.