CVE-2026-48581
Analyzed
Analyzed - Analysis Complete
Insufficient Access Control in Microsoft Surface Elevates Privileges
Vulnerability report for CVE-2026-48581, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-14
Last updated on: 2026-07-24
Assigner: Microsoft Corporation
Description
Description
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| microsoft | surface_go_2_1901_firmware | * |
| microsoft | surface_go_2_1926_firmware | * |
| microsoft | surface_go_2_1927_firmware | * |
| microsoft | surface_go_3_1901_firmware | * |
| microsoft | surface_go_3_1926_firmware | * |
| microsoft | surface_go_3_2022_firmware | * |
| microsoft | surface_hub_firmware | * |
| microsoft | surface_hub_2s_firmware | * |
| microsoft | surface_hub_2s_85_firmware | * |
| microsoft | surface_hub_3_50_firmware | * |
| microsoft | surface_hub_3_85_firmware | * |
| microsoft | surface_laptop_go_1943_firmware | * |
| microsoft | surface_laptop_go_2_2013_firmware | * |
| microsoft | surface_laptop_go_3_2013_firmware | * |
| microsoft | surface_pro_7+_1960_firmware | * |
| microsoft | surface_pro_7+_with_lte_advanced_1961_firmware | * |
| microsoft | surface_pro_8_1983_firmware | * |
| microsoft | surface_pro_8_for_business_1983_firmware | * |
| microsoft | surface_pro_8_for_business_with_lte_advanced_1982_firmware | * |
| microsoft | surface_laptop_4_1979_firmware | * |
| microsoft | surface_laptop_4_1950_firmware | * |
| microsoft | surface_laptop_4_1951_firmware | * |
| microsoft | surface_laptop_4_1952_firmware | * |
| microsoft | surface_laptop_4_1953_firmware | * |
| microsoft | surface_laptop_4_1958_firmware | * |
| microsoft | surface_laptop_4_1959_firmware | * |
| microsoft | surface_laptop_4_1978_firmware | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1220 | The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets. |