IT

Tracker / CVE-2026-48581

CVE-2026-48581

High 7.8

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

Affected products and versions

microsoft surface_go_2_1901_firmware
microsoft surface_go_2_1926_firmware
microsoft surface_go_2_1927_firmware
microsoft surface_go_3_1901_firmware
microsoft surface_go_3_1926_firmware
microsoft surface_go_3_2022_firmware
microsoft surface_hub_2s_85_firmware
microsoft surface_hub_2s_firmware
microsoft surface_hub_3_50_firmware
microsoft surface_hub_3_85_firmware
microsoft surface_hub_firmware
microsoft surface_laptop_4_1950_firmware
microsoft surface_laptop_4_1951_firmware
microsoft surface_laptop_4_1952_firmware
microsoft surface_laptop_4_1953_firmware
microsoft surface_laptop_4_1958_firmware
microsoft surface_laptop_4_1959_firmware
microsoft surface_laptop_4_1978_firmware
microsoft surface_laptop_4_1979_firmware
microsoft surface_laptop_go_1943_firmware
microsoft surface_laptop_go_2_2013_firmware
microsoft surface_laptop_go_3_2013_firmware
microsoft surface_pro_7\+_1960_firmware
microsoft surface_pro_7\+_with_lte_advanced_1961_firmware
microsoft surface_pro_8_1983_firmware
microsoft surface_pro_8_for_business_1983_firmware
microsoft surface_pro_8_for_business_with_lte_advanced_1982_firmware

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References