Impact
Windows Narrator Braille contains an improper neutralization of special elements used in a command, resulting in a command injection flaw (CWE‑77). The vulnerability enables an authorized local attacker to execute arbitrary commands with elevated privileges, effectively allowing privilege escalation on the compromised system.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2 and 22H2; Windows 11 versions 24H2, 25H2 and 26H1; Windows Server 2019 (both standard and Server Core); Windows Server 2022; Windows Server 2025 (both standard and Server Core). The affected builds span x86, x64, and arm64 architectures.
Risk and Exploitability
The CVSS score of 7.8 signifies high severity, yet the EPSS score of less than 1% indicates a low but nonzero chance of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation. Based on the description, it is inferred that an attacker must possess local, authenticated credentials to trigger the injection, which routes to privilege escalation once the vulnerability is leveraged.
OpenCVE Enrichment