CyberICT

CVE-2026-48581

Microsoft · Published July 14, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Surface Broker SDMA Elevation of Privilege Vulnerability. Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

Affected Products

  • Surface Windows Dev Kit
  • Microsoft Surface Hub
  • Microsoft Surface Laptop Go 2
  • Surface Laptop 4 with AMD Processor

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C