Impact
An insufficiently granular access control mechanism in Microsoft Surface devices allows an attacker with existing authorized access to elevate their privileges locally, as identified by CWE-1220. The flaw enables a user who already has permissions on the device to gain higher privileges, potentially enabling further compromise of the device or surrounding network resources. The impact is limited to the device where the attacker already has access, and does not allow remote exploitation.
Affected Systems
Microsoft Surface Go, Surface Hub, Surface Laptop Go, Surface Laptop Go 3, Surface Pro, Surface Pro 8, Surface Laptop 4 with AMD Processor, Surface Laptop 4 with Intel Processor, Surface Windows Dev Kit. No specific firmware or OS version details are disclosed; the vulnerability applies to all listed Surface devices.
Risk and Exploitability
The CVSS score of 7.8 classifies this as high severity, yet the EPSS score is below 1 percent and the vulnerability is not listed in the CISA KEV catalog, indicating low likelihood of exploitation in the wild. The attack vector is local; an adversary must already have authorized or physical access to the target device. Combined, the overall risk is moderate but remediation is strongly recommended to eliminate the privilege escalation pathway.
OpenCVE Enrichment