7.8
CVE-2026-48581
- EPSS 0.21%
- Veröffentlicht 14.07.2026 17:05:46
- Zuletzt bearbeitet 24.07.2026 13:37:22
- CVE-Watchlists
- Unerledigt
Surface Broker SDMA Elevation of Privilege Vulnerability
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Surface Go 2 1901 Firmware Version-
Microsoft ≫ Surface Go 2 1926 Firmware Version-
Microsoft ≫ Surface Go 2 1927 Firmware Version-
Microsoft ≫ Surface Go 3 1901 Firmware Version-
Microsoft ≫ Surface Go 3 1926 Firmware Version-
Microsoft ≫ Surface Go 3 2022 Firmware Version-
Microsoft ≫ Surface Hub Firmware Version-
Microsoft ≫ Surface Hub 2s Firmware Version-
Microsoft ≫ Surface Hub 2s 85 Firmware Version-
Microsoft ≫ Surface Hub 3 50 Firmware Version-
Microsoft ≫ Surface Hub 3 85 Firmware Version-
Microsoft ≫ Surface Laptop Go 1943 Firmware Version-
Microsoft ≫ Surface Laptop Go 2 2013 Firmware Version-
Microsoft ≫ Surface Laptop Go 3 2013 Firmware Version-
Microsoft ≫ Surface Pro 7+ 1960 Firmware Version-
Microsoft ≫ Surface Pro 8 1983 Firmware Version-
Microsoft ≫ Surface Laptop 4 1979 Firmware Version-
Microsoft ≫ Surface Laptop 4 1950 Firmware Version-
Microsoft ≫ Surface Laptop 4 1951 Firmware Version-
Microsoft ≫ Surface Laptop 4 1952 Firmware Version-
Microsoft ≫ Surface Laptop 4 1953 Firmware Version-
Microsoft ≫ Surface Laptop 4 1958 Firmware Version-
Microsoft ≫ Surface Laptop 4 1959 Firmware Version-
Microsoft ≫ Surface Laptop 4 1978 Firmware Version-
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.119 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-1220 Insufficient Granularity of Access Control
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48581