The specific flaw exists within the HelpPane executable. The issue lies in the validation of the integrity level of the COM client, which is performed with a comparison against the integrity level of the desktop's shell. An attacker can leverage this vulnerability to execute code under the context of the user at medium integrity.
Microsoft has issued an update to correct this vulnerability. More details can be found at:
|Ashutosh Mehra (https://twitter.com/ashutoshmehra)