Impact
Microsoft Surface Management Services contains an improper input validation flaw that permits an attacker with authorized network access to send crafted data to the service and execute arbitrary code on the device. The vulnerability is identified as CWE‑20, leading to potential unilateral compromise, data modification, and full device takeover. The description states that the flaw allows code execution over a network, indicating a high‑impact remote code execution scenario.
Affected Systems
The only affected product listed is Microsoft Surface Management Services. No specific version ranges are disclosed by the CNA, and the update guide does not mention an available patch. Consequently, it is inferred that any current and future releases of Surface Management Services that have not been explicitly fixed remain potentially vulnerable until an official fix is issued.
Risk and Exploitability
The CVSS score of 9.9 marks the issue as critical, while an EPSS score of less than 1% indicates exploitation attempts are currently rare. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker who is authenticated or otherwise authorized to send input to the Surface Management Services endpoint over the network; the lack of input boundaries enables code execution on the affected device.
OpenCVE Enrichment