7.1
CVE-2025-21194
- EPSS 0.16%
- Published 11.02.2025 18:15:30
- Last modified 08.07.2025 14:14:50
- Source secure@microsoft.com
- Teams watchlist Login
- Open Login
Microsoft Surface Security Feature Bypass Vulnerability
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Microsoft ≫ Surface Hub 2s Firmware Version-
Microsoft ≫ Surface Laptop Go Firmware Version-
Microsoft ≫ Surface Laptop Go 2 Firmware Version-
Microsoft ≫ Surface Hub 3 50 Firmware Version-
Microsoft ≫ Surface Hub 2s Firmware Version-
Microsoft ≫ Surface Laptop Go 3 Firmware Version-
Microsoft ≫ Surface Go 3 Firmware Version-
Microsoft ≫ Surface Laptop Go 2 Firmware Version-
Microsoft ≫ Surface Pro 9 With 5g 1997 Firmware Version-
Microsoft ≫ Surface Pro 9 With 5g 1996 Firmware Version-
Microsoft ≫ Surface Laptop 3 1867 Firmware Version-
Microsoft ≫ Surface Laptop 3 1872 Firmware Version-
Microsoft ≫ Surface Laptop 4 1958 Firmware Version-
Microsoft ≫ Surface Laptop 4 1950 Firmware Version-
Microsoft ≫ Surface Laptop 4 1952 Firmware Version-
Microsoft ≫ Surface Laptop 4 1978 Firmware Version-
Microsoft ≫ Windows Dev Kit Firmware Version-
Microsoft ≫ Surface Hub 2s 85 Firmware Version-
Microsoft ≫ Surface Hub 3 50 Firmware Version-
Microsoft ≫ Surface Hub 3 85 Firmware Version-
Microsoft ≫ Surface Pro 8 1983 Firmware Version-
Microsoft ≫ Surface Hub 3 85 Firmware Version-
Microsoft ≫ Surface Hub 2s 85 Firmware Version-
Microsoft ≫ Surface Go 3 1926 Firmware Version-
Microsoft ≫ Surface Go 3 1901 Firmware Version-
Microsoft ≫ Surface Go 3 2022 Firmware Version-
Microsoft ≫ Surface Go 2 1926 Firmware Version-
Microsoft ≫ Surface Go 2 1901 Firmware Version-
Microsoft ≫ Surface Go 2 1927 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.16% | 0.371 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
secure@microsoft.com | 7.1 | 1.2 | 5.9 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.