Command Injection Vulnerability in Windows Narrator Braille by Microsoft
CVE-2026-58635

7.8HIGH

Key Information:

Badges

📈 Score: 155👾 Exploit Exists🟡 Public PoC

What is CVE-2026-58635?

CVE-2026-58635 is a command injection vulnerability affecting the Windows Narrator Braille software, which is part of Microsoft's accessibility features. This software is designed to assist users with visual impairments by providing braille output in conjunction with other assistive technologies. The flaw arises from improper handling of special command elements, allowing an authorized attacker to perform command injections, leading to potential privilege escalation on the local system. If exploited, this vulnerability could enable an attacker to gain elevated access and control over the system, posing serious risks to the organization’s security posture and integrity.

Potential impact of CVE-2026-58635

  1. Privilege Escalation: The primary impact of this vulnerability is the ability for an attacker to escalate their privileges, allowing them to execute unauthorized commands with higher permissions. This can lead to unauthorized access to sensitive data or critical system components.

  2. Local System Compromise: By gaining elevated privileges, an attacker can compromise the integrity of the affected system, potentially leading to the installation of malware or unauthorized software, which could further threaten the entire network.

  3. Data Breaches: With increased access rights, attackers can access, modify, or exfiltrate sensitive data, resulting in significant data breaches that could have serious legal and financial repercussions for the organization.

Affected Version(s)

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.9020

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7548

Windows 10 Version 22H2 32-bit Systems 10.0.19045.0 < 10.0.19045.7548

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.