Junglewise Threat Intelligence

CVE-2026-58635: Microsoft Windows Narrator Braille command injection privilege escalation

CVE-2026-58635 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A vulnerability in the Windows Narrator Braille accessibility feature could allow a user with basic access to a computer to gain full administrative control. This component is designed to support Braille displays for visually impaired users. If exploited, an attacker could bypass security restrictions to access sensitive data or install malicious software on the affected system.

Technical details

A command injection vulnerability (CWE-77) exists in the Windows Narrator Braille component due to improper neutralization of special elements used in a command. An attacker with low-privileged local access can exploit this flaw to execute arbitrary commands with elevated system privileges. The attack vector is local and requires no user interaction. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2019 All versions
  • Microsoft Windows Server 2022 All versions

Timeline

  • 2026-07-14: advisory: Initial advisory published by Microsoft and NVD.
  • 2026-07-14: patched: Security updates made available.

References

Related threats