Junglewise Threat Intelligence

CVE-2026-55013: Microsoft Windows Remote Help privilege spoofing via search path

CVE-2026-55013 · Severity: high · CVSS 7.1 · Published 2026-08-20

Vendors: Microsoft.

Executive brief

Windows Remote Help is a built-in Microsoft utility that allows users to request and receive remote assistance for technical issues. A local, authorized attacker can exploit an uncontrolled search path element to impersonate other users or elevate privileges through DLL injection or executable spoofing. This could lead to unauthorized access to sensitive data or system compromise on affected machines.

Technical details

The vulnerability is a DLL search order hijacking (or similar search path control issue) in Windows Remote Help Defense, classified as a spoofing vulnerability. The flaw allows an authorized local attacker to place a malicious library or executable in an uncontrolled search path location that the Remote Help utility searches during startup or operation. By controlling what gets loaded, an attacker can impersonate legitimate components or escalate privileges. The attack requires local access and user authorization but does not require administrative rights. A patch is available from Microsoft via their Security Update Guide.

Affected products

  • Microsoft Windows Remote Help <UNKNOWN>

Timeline

  • 2026-08-20: disclosed

References

Related threats