Microsoft Intune’s “What’s new” page for the Week of September 7, 2026 is short — a single entry. But the item it contains is one every helpdesk and endpoint team should act on: Remote Help for Windows version 5.2.1040.0 is now available, and it is the fixed build for two Important-rated security flaws.

Here’s the full picture — what changed, why the version matters, and what IT admins should do about it.


The change: Remote Help for Windows 5.2.1040.0

Per Microsoft, the new release “updates subscription metadata for E3, E5, and E7 licenses,” and Remote Help features are unchanged from version 5.2.1037.0.

Read on its own, that sounds like housekeeping: a version bump plus a licensing metadata refresh. There is more under the hood than the What’s New page spells out, and if you run Remote Help in production, this build should be treated as required rather than optional.

Applies to: Windows


The security story behind build 5.2.1040.0

On August 20, 2026, the Microsoft Security Response Center published two advisories for Windows Remote Help. Build 5.2.1040.0 is the fixed version for both:

  • CVE-2026-55013 — Windows Remote Help Defense Spoofing Vulnerability. Rated Important, CVSS 3.1 base score 7.1. Classified as CWE-427, an uncontrolled search path element: Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally. Microsoft lists no public disclosure and no known exploitation, with an exploitation assessment of less likely — but marks customer action required.
  • CVE-2026-55015 — Microsoft Remote Help Denial of Service Vulnerability. Rated Important, CVSS 5.5. The same uncontrolled-search-path family: an authorized local attacker could disrupt the Remote Help app.

Both flaws require an already-authenticated attacker with local access, which is why they land at Important rather than Critical. Even so, for a tool that helpdesks use to reach into endpoints, “authorized local attacker” is a realistic threat model — a compromised standard user on a corporate laptop is exactly the attacker profile these advisories describe.

The affected range is Windows Remote Help 5.0.0.0 through 5.2.1039.x; anything below 5.2.1040.0 counts as unpatched. Microsoft’s update catalog lists the package at roughly 7.5 MB, notes that it replaces 5.2.1037.0, requires no restart, and should not prompt the user.


Why the E3, E5, and E7 metadata matters

The “E3, E5, and E7” language in the What’s New post isn’t filler. Starting July 2026, Microsoft began folding Intune advanced capabilities — including Remote Help — into Microsoft 365 E3, and into E5 and E7 alongside Endpoint Privilege Management, Microsoft Cloud PKI, and Enterprise App Management. In practice, the number of tenants entitled to run Remote Help jumped sharply, and many organizations received the new service plans switched on by default.

A release that touches subscription metadata for those tiers is a good prompt to verify two things:

  • that Remote Help is enabled at the tenant level — Remote Help ships off by default, and
  • that licensing is assigned to both helpers and sharers — Remote Help has never been a helper-only license.

If you are on E3, E5, or E7 and assumed Remote Help required a separate add-on, use this release as the reminder to confirm what your tenant actually provisions. We covered the original licensing shift in our Intune 2606 breakdown.


What changed — and what did not

It is easy to confuse this update with the bigger Remote Help news from the previous service release. Service Release 2608 introduced unattended Remote Help sessions for Windows — a genuine capability change. This 5.2.1040.0 release is not that update.

Microsoft is explicit: features are unchanged from 5.2.1037.0, the build that delivered performance and reliability improvements back in June (we covered that release here). So think of the September 7 update as servicing plus licensing plumbing, not new functionality.


What IT teams should do now

  1. Inventory both sides of the session. Check helper workstations and the user devices where the Remote Help app is installed. The flaw affects the client, not Windows itself — patching the OS does not remediate it.
  2. Set 5.2.1040.0 as the minimum accepted build. If Remote Help was deployed as a Win32 app, update the app package or confirm auto-update is pulling the new build. If you distribute it through the Enterprise App Catalog, pick up the latest version.
  3. Pilot, then deploy broadly. On a representative device, test sign-in, screen sharing, elevation prompts, remote launch, and session closure before pushing org-wide.
  4. Verify — do not assume. A successful Intune deployment command is not proof that every endpoint updated. Re-query app inventory and treat devices below 5.2.1040.0 as outstanding remediation.
  5. Review your guardrails. Remote Help relies on Entra sign-in, RBAC, Conditional Access, and session auditing. Require MFA for helpers where practical, keep elevation rights tightly scoped, and if you have enabled unattended access, keep its dedicated RBAC permission limited to trusted support groups.
  6. Re-confirm licensing. Validate that both helpers and sharers are licensed and that the capability is enabled in the tenant.

The bottom line

The Week of September 7, 2026 update is a good example of why the Intune “What’s new” page rewards a careful read. A one-line entry that says features unchanged is, in this case, also a security servicing event — two Important-rated CVEs sit underneath that version number. Combined with the licensing metadata refresh for E3, E5, and E7, this is a small release with a wide blast radius: more tenants than ever now run Remote Help, and every one of them should confirm the client is on 5.2.1040.0 or later.

Follow me at https://x.com/kkaminsk for ongoing Intune and endpoint management coverage — and check back regularly as we track every Intune update.

This article is based on Microsoft’s official What’s new in Microsoft Intune documentation and corresponding Microsoft Security Response Center advisories. Feature availability may vary by tenant due to gradual rollout.