CVE Tools

CVE-2026-61358

Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability

Published: Aug 11, 2026Updated: Aug 16, 2026 Sources: CVE List NVDCWE-59

Description

Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

In plain language

AI Act now

CVE-2026-61358 is a Windows local privilege escalation bug in ATBroker.exe; if someone already has a legitimate foothold on your device, patching is urgent for Windows 10/11 and Windows Server.

Executive summary

An elevation of privilege issue (CWE-59: improper link resolution before file access) in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized local attacker to elevate privileges on Windows 10/11 and Windows Server; fixed builds are listed by Microsoft for multiple releases.

If affected, business impact
Device takeover by a local attackerPotential ransomware preparationFull access to data and accountsService disruption from compromise

What to do now

  1. Check whether your organization runs any of these affected systems: Windows 10, Windows 11, Windows Server 2019, Windows Server 2022, or Windows Server 2025.
  2. Identify your current Windows build number on each affected machine (Settings → System → About, or run winver).
  3. Compare each machine’s build against the fixed versions from Microsoft for CVE-2026-61358 and note any machine that is below the fixed build.
  4. Patch the affected machines by installing the Microsoft security update referenced for CVE-2026-61358 from the MSRC update guide.
  5. Verify the patch is installed (re-check the Windows build number) and ensure restart completes successfully.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:LAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 18 more affected products View all →

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Collection
Discovery
View detailed technique mapping

References

4

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-61358 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows