Improper Access Control Vulnerability in Windows Remote Help Defense
CVE-2026-55014

7.8HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
14 July 2026

What is CVE-2026-55014?

An improper access control vulnerability exists in Windows Remote Help Defense that permits an authorized attacker to elevate their privileges locally. Exploiting this vulnerability could allow the attacker to gain unintended access to sensitive resources, potentially leading to further security risks within the impacted system. It is essential for users to apply the relevant security patches provided by Microsoft to mitigate this vulnerability and protect their systems.

Affected Version(s)

Windows Remote Help 5.0.0.0 < 5.2.1037.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.