ID:13041 - Exploit for Command injection in Microsoft Windows and Windows Server - CVE-2026-58635

 
Main Vulnerability Database Exploits ID:13041 - Exploit for Command injection in Microsoft Windows and Windows Server - CVE-2026-58635

ID:13041 - Exploit for Command injection in Microsoft Windows and Windows Server - CVE-2026-58635

Published: September 4, 2026


Vulnerability identifier: #VU137953
Vulnerability risk: Low
CVE-ID: CVE-2026-58635
CWE-ID: CWE-77
Exploitation vector: Local access
Vulnerable software:
Microsoft Windows
Windows Server

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to command injection in Windows Narrator Braille when processing special elements used in a command. A local user can inject crafted command elements to escalate privileges.

Successful exploitation can execute code in the security context of the NT AUTHORITY\Network Service account.


Remediation

Install security update from vendor's website.