Impact
An uncontrolled search path element in Windows Remote Help can be exploited by an authorized attacker with local privileges to cause a denial of service on the affected system. The vulnerability stems from the ability to alter the search path used by the service, leading to incorrect resolution of executable files and subsequently crashing or stopping the service. This primarily jeopardizes the availability of Windows Remote Help for legitimate users on the compromised machine. The weakness is identified as CWE‑427, which indicates improper control of the environment path used by software.
Affected Systems
Microsoft’s Windows Remote Help component is affected. Version details are not listed in the official advisories. Organizations using Windows Remote Help on any Windows platform should consider the service susceptible to this local denial of service condition.
Risk and Exploitability
The CVSS score for this issue is 5.5, reflecting a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting the probability of widespread exploitation is currently unknown. The attack vector is inferred to be local, requiring the attacker to be authorized and possess local user privileges to manipulate the search path. Given the lack of an immediate patch or official workaround, exposure is limited to environments where Windows Remote Help is enabled and usable by privileged users.
OpenCVE Enrichment