CVE-2026-58635
HIGHMicrosoft Windows 10 Version 1809 - Windows Narrator Braille Elevation of Privilege Vulnerability
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2026-58635. PoCs published by DavidCarliez.
AI-analyzed exploit summary This PoC exploits a local privilege escalation vulnerability (CVE-2026-58635) in Windows Narrator's Braille (BRLTTY) component by abusing the `brlapi_setParameter` function to execute arbitrary payloads as LocalService, then leveraging SigmaPotato for token impersonation to achieve SYSTEM privileges.
Description
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
Exploits (1)
This PoC exploits a local privilege escalation vulnerability (CVE-2026-58635) in Windows Narrator's Braille (BRLTTY) component by abusing the `brlapi_setParameter` function to execute arbitrary payloads as LocalService, then leveraging SigmaPotato for token impersonation to achieve SYSTEM privileges.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H