Impact
The flaw is an improper access‑control check in the Windows Remote Help Defense component that allows a local user with authorized access to raise their own privileges. This elevation‑of‑privilege weakness (CWE‑284) can enable the attacker to gain administrative or system level rights, permitting full compromise of the affected machine.
Affected Systems
The vulnerability affects the Microsoft Windows Remote Help component. Because no specific product versions are listed, any installation of Windows Remote Help where the Remote Help Defense feature is enabled could be affected. The scope is local to the host running the service.
Risk and Exploitability
The CVSS score of 7.8 indicates medium‑to‑high severity, while the EPSS score of less than 1 % suggests that exploitation is considered unlikely at present. The flaw is not listed in the CISA KEV catalog, implying that no widespread public exploitation has been observed. An attacker must already possess local authorized access to the machine and then leverage the defective access‑control logic inside the Remote Help Defense component to elevate privileges.
OpenCVE Enrichment