Impact
The vulnerability arises from an uncontrolled search path element in the Windows Remote Help Defense component. This flaw enables an attacker who already has authorized access on the host to manipulate the search path and inject a forged executable, effectively allowing the attacker to spoof local operations. The lack of validation of the path introduces a local privilege escalation vector that can be leveraged to present malicious content or commands to the user or system without overtly triggering standard security checks.
Affected Systems
Microsoft Windows Remote Help is the affected product. No specific version range is listed, indicating that the issue may exist across all supported releases of the feature until a patch is applied.
Risk and Exploitability
The CVSS score of 7.1 reflects a medium to high severity. Since the evidence suggests an authorized attacker is required, the attack vector is local and relies on existing privileges. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, implying that there is no known widespread exploitation yet. However, the ability to spoof locally remains a concern for users and administrators who enable Remote Help, especially in environments where privilege ranges are broad.
OpenCVE Enrichment