Impact
An untrusted search path in the Windows Narrator Braille driver allows an authorized local user to elevate privileges. By exploiting this search‑path flaw, an attacker who already has an authenticated local account can execute code with higher rights, potentially gaining administrative privileges. This could let the attacker install malicious software, exfiltrate sensitive data, or alter system configurations, thereby compromising confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 version 23H2; as well as Windows Server 2019, 2022, and 2025, including Server Core installations. All builds listed by the CNA are affected.
Risk and Exploitability
The CVSS score of 7.8 signals high severity for local attacks, while the EPSS score is below 1% and the vulnerability is not in CISA’s KEV catalog. The likely attack vector is local; an authorized user can place a malicious executable in the Braille driver’s search path and trigger its execution, thereby raising privileges. The overall risk is moderate to high for systems where the Narrator Braille feature is enabled and where local users might have the capability to add files to the driver’s directory.
OpenCVE Enrichment