CVE-2026-48581
Microsoft · Published July 14, 2026
7.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Surface Broker SDMA Elevation of Privilege Vulnerability. Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
Affected Products
- Surface Windows Dev Kit
- Microsoft Surface Hub
- Microsoft Surface Laptop Go 2
- Surface Laptop 4 with AMD Processor
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C