CVE-2026-55013

high
EUVD alias: EUVD-2026-63697
Assigned by CNA: microsoft
Published 2026-08-20 · Modified 2026-08-20
CVSS v3
7.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
CVSS v4 NEW
not yet in upstream
VIR risk
7.1

Description

<p>Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.</p>

Predictions

Exploit likelihood
70%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Microsoft Security Response Center · View original ↗ · proprietary-no-redistribution
Full prose not cached — VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.

Affected

VendorProductVersion
microsoftMicrosoft Exchange Online
microsoftWindows Server 2012
microsoftWindows Server 2012 (Server Core installation)
microsoftWindows Server 2012 R2
microsoftWindows Server 2012 R2 (Server Core installation)
microsoftMicrosoft Excel 2016 (32-bit edition)
microsoftMicrosoft Excel 2016 (64-bit edition)
microsoftMicrosoft PowerPoint 2016 (32-bit edition)
microsoftMicrosoft PowerPoint 2016 (64-bit edition)
microsoftMicrosoft Word 2016 (32-bit edition)
microsoftMicrosoft Word 2016 (64-bit edition)
microsoftMicrosoft Access 2016 (32-bit edition)
microsoftMicrosoft Access 2016 (64-bit edition)
microsoftMicrosoft Office 2016 (32-bit edition)
microsoftMicrosoft Office 2016 (64-bit edition)
microsoftMicrosoft Outlook 2016 (32-bit edition)
microsoftMicrosoft Outlook 2016 (64-bit edition)
microsoftWindows Server 2016
microsoftOffice Online Server
microsoftWindows 10 Version 1607 for 32-bit Systems
microsoftWindows 10 Version 1607 for x64-based Systems
microsoftWindows Server 2016 (Server Core installation)
microsoftMicrosoft SharePoint Enterprise Server 2016
microsoftWindows 10 Version 1809 for 32-bit Systems
microsoftWindows 10 Version 1809 for x64-based Systems
microsoftWindows Server 2019
microsoftWindows Server 2019 (Server Core installation)
microsoftMicrosoft Office 2019 for 32-bit editions
microsoftMicrosoft Office 2019 for 64-bit editions
microsoftMicrosoft SharePoint Server 2019

OS impact

windows Windows Affected 1 release
VersionStatusFixed in
Affected

References

CWEs

CWE-427

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.