Description
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insufficiently granular access control mechanism in Microsoft Surface devices allows an attacker with existing authorized access to elevate their privileges locally, as identified by CWE-1220. The flaw enables a user who already has permissions on the device to gain higher privileges, potentially enabling further compromise of the device or surrounding network resources. The impact is limited to the device where the attacker already has access, and does not allow remote exploitation.

Affected Systems

Microsoft Surface Go, Surface Hub, Surface Laptop Go, Surface Laptop Go 3, Surface Pro, Surface Pro 8, Surface Laptop 4 with AMD Processor, Surface Laptop 4 with Intel Processor, Surface Windows Dev Kit. No specific firmware or OS version details are disclosed; the vulnerability applies to all listed Surface devices.

Risk and Exploitability

The CVSS score of 7.8 classifies this as high severity, yet the EPSS score is below 1 percent and the vulnerability is not listed in the CISA KEV catalog, indicating low likelihood of exploitation in the wild. The attack vector is local; an adversary must already have authorized or physical access to the target device. Combined, the overall risk is moderate but remediation is strongly recommended to eliminate the privilege escalation pathway.

Generated by OpenCVE AI on July 31, 2026 at 09:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply any Microsoft Surface firmware or OS updates that address CVE-2026-48581.
  • Review and restrict user privileges, enforcing a least‑privilege policy to limit the potential impact of future local privilege escalation flaws.
  • Monitor the devices for any unauthorized privilege escalation or anomalous behavior that might indicate exploitation.

Generated by OpenCVE AI on July 31, 2026 at 09:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
Title Surface Broker SDMA Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft surface Go 2
Microsoft surface Go 3
Microsoft surface Hub
Microsoft surface Laptop 4 Amd Processor
Microsoft surface Laptop 4 Intel Processor
Microsoft surface Laptop Go 2
Microsoft surface Laptop Go 3
Microsoft surface Pro 7
Microsoft surface Pro 8
Microsoft surface Windows Dev Kit
Weaknesses CWE-1220
CPEs cpe:2.3:h:microsoft:surface_go_2:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_go_3:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_hub:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_laptop_4_AMD_processor:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_laptop_4_intel_processor:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_laptop_go_2:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_laptop_go_3:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_pro_7:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_pro_8:*:*:*:*:*:*:*:*
cpe:2.3:h:microsoft:surface_windows_dev_kit:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft surface Go 2
Microsoft surface Go 3
Microsoft surface Hub
Microsoft surface Laptop 4 Amd Processor
Microsoft surface Laptop 4 Intel Processor
Microsoft surface Laptop Go 2
Microsoft surface Laptop Go 3
Microsoft surface Pro 7
Microsoft surface Pro 8
Microsoft surface Windows Dev Kit
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Surface Go 2 Surface Go 3 Surface Hub Surface Laptop 4 Amd Processor Surface Laptop 4 Intel Processor Surface Laptop Go 2 Surface Laptop Go 3 Surface Pro 7 Surface Pro 8 Surface Windows Dev Kit
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:54:10.226Z

Reserved: 2026-05-21T20:00:35.246Z

Link: CVE-2026-48581

cve-icon Vulnrichment

Updated: 2026-07-14T17:45:09.739Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:15:06Z

Weaknesses
  • CWE-1220

    Insufficient Granularity of Access Control