Executive brief
A vulnerability in the Windows Narrator Braille accessibility feature could allow a user with basic access to a computer to gain full administrative control. This component is designed to support Braille displays for visually impaired users. If exploited, an attacker could bypass security restrictions to access sensitive data or install malicious software on the affected system.
Technical details
A command injection vulnerability (CWE-77) exists in the Windows Narrator Braille component due to improper neutralization of special elements used in a command. An attacker with low-privileged local access can exploit this flaw to execute arbitrary commands with elevated system privileges. The attack vector is local and requires no user interaction. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-07-14: advisory: Initial advisory published by Microsoft and NVD.
- 2026-07-14: patched: Security updates made available.