Description
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
Title Surface Broker SDMA Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft surface Go 2
Microsoft surface Go 3
Microsoft surface Hub
Microsoft surface Laptop 4 Amd Processor
Microsoft surface Laptop 4 Intel Processor
Microsoft surface Laptop Go 2
Microsoft surface Laptop Go 3
Microsoft surface Pro 7
Microsoft surface Pro 8
Microsoft surface Windows Dev Kit
Weaknesses CWE-1220
CPEs cpe:2.3:h:microsoft:surface_go_2:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_go_3:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_hub:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_laptop_4_AMD_processor:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_laptop_4_intel_processor:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_laptop_go_2:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_laptop_go_3:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_pro_7:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_pro_8:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_windows_dev_kit:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft surface Go 2
Microsoft surface Go 3
Microsoft surface Hub
Microsoft surface Laptop 4 Amd Processor
Microsoft surface Laptop 4 Intel Processor
Microsoft surface Laptop Go 2
Microsoft surface Laptop Go 3
Microsoft surface Pro 7
Microsoft surface Pro 8
Microsoft surface Windows Dev Kit
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Surface Go 2 Surface Go 2 1901 Surface Go 2 1901 Firmware Surface Go 2 1926 Surface Go 2 1926 Firmware Surface Go 2 1927 Surface Go 2 1927 Firmware Surface Go 3 Surface Go 3 1901 Surface Go 3 1901 Firmware Surface Go 3 1926 Surface Go 3 1926 Firmware Surface Go 3 2022 Surface Go 3 2022 Firmware Surface Hub Surface Hub 2s Surface Hub 2s 85 Surface Hub 2s 85 Firmware Surface Hub 2s Firmware Surface Hub 3 50 Surface Hub 3 50 Firmware Surface Hub 3 85 Surface Hub 3 85 Firmware Surface Hub Firmware Surface Laptop 4 1950 Surface Laptop 4 1950 Firmware Surface Laptop 4 1951 Surface Laptop 4 1951 Firmware Surface Laptop 4 1952 Surface Laptop 4 1952 Firmware Surface Laptop 4 1953 Surface Laptop 4 1953 Firmware Surface Laptop 4 1958 Surface Laptop 4 1958 Firmware Surface Laptop 4 1959 Surface Laptop 4 1959 Firmware Surface Laptop 4 1978 Surface Laptop 4 1978 Firmware Surface Laptop 4 1979 Surface Laptop 4 1979 Firmware Surface Laptop 4 Amd Processor Surface Laptop 4 Intel Processor Surface Laptop Go 1943 Surface Laptop Go 1943 Firmware Surface Laptop Go 2 Surface Laptop Go 2 2013 Surface Laptop Go 2 2013 Firmware Surface Laptop Go 3 Surface Laptop Go 3 2013 Surface Laptop Go 3 2013 Firmware Surface Pro 7 Surface Pro 7\+ 1960 Surface Pro 7\+ 1960 Firmware Surface Pro 7\+ With Lte Advanced 1961 Surface Pro 7\+ With Lte Advanced 1961 Firmware Surface Pro 8 Surface Pro 8 1983 Surface Pro 8 1983 Firmware Surface Pro 8 For Business 1983 Surface Pro 8 For Business 1983 Firmware Surface Pro 8 For Business With Lte Advanced 1982 Surface Pro 8 For Business With Lte Advanced 1982 Firmware Surface Windows Dev Kit
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-14T17:21:14.703Z

Reserved: 2026-05-21T20:00:35.246Z

Link: CVE-2026-48581

cve-icon Vulnrichment

Updated: 2026-07-14T17:45:09.739Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-14T17:16:50.767

Modified: 2026-07-24T13:37:22.080

Link: CVE-2026-48581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:15:06Z

Weaknesses