Skip to content
MicrosoftCVE-2026-55013

Microsoft Windows Remote Help: spoofing

High7.1CVE-2026-55013 · Published Aug 20, 2026 · updated Aug 26, 2026

Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.

Microsoft advisory

Affected versions

PackageAffectedFixed in
Windows Remote Help
Product
>= 5.0.0.0, < 5.2.1040.05.2.1040.0
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-427

More Microsoft advisories

All Microsoft
Advisory
Microsoft Copilot in Azure: server-side request forgery
High7.7Aug 20
Microsoft Office Word: improper input validation
Medium6.5Aug 20
Microsoft Azure Stack HCI: unauthorized attacker could disclose information over
High8.6Aug 20
Microsoft Azure Virtual Machines: server-side request forgery
High8.5Aug 20
Microsoft Azure ARC: improper authorization
Critical10.0Aug 20
Microsoft Partner Center: insecure direct object reference
High8.6Aug 20

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.