• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-58635: privilege escalation in Microsoft Windows 10 Version 1809

Local, low-privileged users can exploit a command-injection flaw in the Windows Narrator Braille component to obtain elevated privileges on affected Windows builds. CVE-2026-58635 affects multiple Windows 10, Windows 11 and Windows Server branches (see affected builds below); Microsoft notes affected ranges starting at 10.0.17763.0 and other branch-specific ranges and provides fixed builds. An attacker requires local access with a low-privilege account (no user interaction) to trigger the issue.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
7.8HIGH
EPSS
0.00322
CWE
CWE-77
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so prioritize updates; the strongest immediate mitigation is to install Microsoft’s fixed builds or restrict local account access until patched.

What is CVE-2026-58635?

Local, low-privileged users can exploit a command-injection flaw in the Windows Narrator Braille component to obtain elevated privileges on affected Windows builds. CVE-2026-58635 affects multiple Windows 10, Windows 11 and Windows Server branches (see affected builds below); Microsoft notes affected ranges starting at 10.0.17763.0 and other branch-specific ranges and provides fixed builds. An attacker requires local access with a low-privilege account (no user interaction) to trigger the issue. The weakness is classified as CWE-77 (Command Injection).

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1809 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.902010.0.17763.9020
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.754810.0.19044.7548
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.754810.0.19045.7548
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.887510.0.26100.8875
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.887510.0.26200.8875
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.252510.0.28000.2525
Windows Server 2019 10.x10.0.17763.0 – before 10.0.17763.902010.0.17763.9020
Windows Server 2019 (Server Core installation) 10.x10.0.17763.0 – before 10.0.17763.902010.0.17763.9020
Windows Server 2022 10.x10.0.20348.0 – before 10.0.20348.538610.0.20348.5386
Windows Server 2025 10.x10.0.26100.0 – before 10.0.26100.3315810.0.26100.33158

Is CVE-2026-58635 being exploited?

Public exploit code is available.

How to fix CVE-2026-58635

  1. Install Microsoft fixes for affected branches (examples include 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548, 10.0.26100.8875, 10.0.26200.8875, 10.0.28000.2525, 10.0.20348.5386, 10.0.26100.33158).
  2. If you cannot patch immediately, restrict or remove untrusted local accounts and limit administrative access on endpoints with Narrator Braille.
  3. Monitor logs and endpoint telemetry for suspicious local process creation and attempts to invoke Narrator Braille components.
  4. Follow Microsoft guidance for any additional mitigations and apply updates through your normal patch management process.

Frequently asked questions

Is CVE-2026-58635 being actively exploited?

Public exploit code is available for CVE-2026-58635.

Which Windows versions are affected by CVE-2026-58635?

Windows 10, Windows 11 and several Windows Server branches are listed as affected; Microsoft provides branch-specific affected ranges (for example starting at 10.0.17763.0 for some 10.x branches) — consult the vendor’s affected list for exact build ranges.

Is there a patch for CVE-2026-58635?

Yes. Microsoft published fixed builds for each affected branch; examples include 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548 and others listed in the vendor’s advisory.

Does CVE-2026-58635 require authentication?

Yes. The flaw requires a local, authorized (low-privilege) account on the affected Windows builds to exploit; no additional user interaction is required.

References