Junglewise Threat Intelligence

CVE-2026-55014: Microsoft Windows Remote Help Defense privilege escalation

CVE-2026-55014 · Severity: high · CVSS 7.8 · Published 2026-07-14

Vendors: Microsoft.

Executive brief

A security vulnerability in Windows Remote Help Defense could allow a user who already has basic access to a computer to gain full administrative control. Windows Remote Help is a built-in tool used for remote technical support and troubleshooting. If exploited, an attacker could bypass security restrictions to access sensitive files, install malicious software, or disrupt system operations.

Technical details

An improper access control vulnerability (CWE-284) exists in Microsoft Windows Remote Help Defense. The flaw allows a locally authenticated attacker with low privileges to bypass security restrictions and elevate their permissions to a higher level, potentially reaching SYSTEM or Administrator status. The attack vector is local, meaning the attacker must already have the ability to execute code on the target system, but it requires no user interaction. Microsoft has addressed this issue in Windows Remote Help versions 5.2.1037.0 and later.

Affected products

  • Microsoft Windows Remote Help Defense 5.0.0.0 to 5.2.1037.0

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD
  • 2026-07-14: patched: Fix available in version 5.2.1037.0

References