Description
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
Published: 2026-07-23
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Surface Management Services contains an improper input validation flaw that permits an attacker with authorized network access to send crafted data to the service and execute arbitrary code on the device. The vulnerability is identified as CWE‑20, leading to potential unilateral compromise, data modification, and full device takeover. The description states that the flaw allows code execution over a network, indicating a high‑impact remote code execution scenario.

Affected Systems

The only affected product listed is Microsoft Surface Management Services. No specific version ranges are disclosed by the CNA, and the update guide does not mention an available patch. Consequently, it is inferred that any current and future releases of Surface Management Services that have not been explicitly fixed remain potentially vulnerable until an official fix is issued.

Risk and Exploitability

The CVSS score of 9.9 marks the issue as critical, while an EPSS score of less than 1% indicates exploitation attempts are currently rare. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker who is authenticated or otherwise authorized to send input to the Surface Management Services endpoint over the network; the lack of input boundaries enables code execution on the affected device.

Generated by OpenCVE AI on August 3, 2026 at 20:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Surface Management Services patch for CVE-2026-54120 as described in the official update guide
  • Restrict the privileges of accounts that can access Surface Management Services to the minimal level required for their role
  • Limit exposure of Surface Management Services by restricting network traffic to approved hosts through firewall rules or network segmentation

Generated by OpenCVE AI on August 3, 2026 at 20:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
Title Microsoft Surface Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft surface Management Services
Weaknesses CWE-20
CPEs cpe:2.3:a:microsoft:surface_management_services:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft surface Management Services
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Surface Management Services
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:15:09.179Z

Reserved: 2026-06-11T20:33:37.836Z

Link: CVE-2026-54120

cve-icon Vulnrichment

Updated: 2026-07-24T12:21:20.146Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T01:17:25.340

Modified: 2026-08-06T00:51:37.770

Link: CVE-2026-54120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses
  • CWE-20

    Improper Input Validation