Description
Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
Published: 2026-08-20
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An uncontrolled search path element in Windows Remote Help can be exploited by an authorized attacker with local privileges to cause a denial of service on the affected system. The vulnerability stems from the ability to alter the search path used by the service, leading to incorrect resolution of executable files and subsequently crashing or stopping the service. This primarily jeopardizes the availability of Windows Remote Help for legitimate users on the compromised machine. The weakness is identified as CWE‑427, which indicates improper control of the environment path used by software.

Affected Systems

Microsoft’s Windows Remote Help component is affected. Version details are not listed in the official advisories. Organizations using Windows Remote Help on any Windows platform should consider the service susceptible to this local denial of service condition.

Risk and Exploitability

The CVSS score for this issue is 5.5, reflecting a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting the probability of widespread exploitation is currently unknown. The attack vector is inferred to be local, requiring the attacker to be authorized and possess local user privileges to manipulate the search path. Given the lack of an immediate patch or official workaround, exposure is limited to environments where Windows Remote Help is enabled and usable by privileged users.

Generated by OpenCVE AI on August 21, 2026 at 00:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Microsoft Security Update Guide for any available patches or advisories concerning Windows Remote Help and apply them when released.
  • If Windows Remote Help is not essential for your operations, disable the service or the corresponding Remote Help functionality to eliminate the attack surface.
  • Review and tighten local account privileges to ensure that only trusted administrators can alter the search path or settings for Remote Help, and monitor system logs for any anomalous attempts to modify environment variables or service behavior.

Generated by OpenCVE AI on August 21, 2026 at 00:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft remote Help
CPEs cpe:2.3:a:microsoft:remote_help:*:*:*:*:*:*:*:*
Vendors & Products Microsoft remote Help

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
Title Microsoft Remote Help Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows-remote-help
Weaknesses CWE-427
CPEs cpe:2.3:a:microsoft:windows-remote-help:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows-remote-help
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Remote Help Windows-remote-help
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-09T19:36:44.558Z

Reserved: 2026-06-16T14:12:44.284Z

Link: CVE-2026-55015

cve-icon Vulnrichment

Updated: 2026-08-21T15:33:24.005Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T22:17:22.080

Modified: 2026-08-26T15:01:41.980

Link: CVE-2026-55015

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T01:30:05Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element