Tracker / CVE-2026-48581
CVE-2026-48581
High 7.8
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
Affected products and versions
| microsoft | surface_go_2_1901_firmware |
|---|---|
| microsoft | surface_go_2_1926_firmware |
| microsoft | surface_go_2_1927_firmware |
| microsoft | surface_go_3_1901_firmware |
| microsoft | surface_go_3_1926_firmware |
| microsoft | surface_go_3_2022_firmware |
| microsoft | surface_hub_2s_85_firmware |
| microsoft | surface_hub_2s_firmware |
| microsoft | surface_hub_3_50_firmware |
| microsoft | surface_hub_3_85_firmware |
| microsoft | surface_hub_firmware |
| microsoft | surface_laptop_4_1950_firmware |
| microsoft | surface_laptop_4_1951_firmware |
| microsoft | surface_laptop_4_1952_firmware |
| microsoft | surface_laptop_4_1953_firmware |
| microsoft | surface_laptop_4_1958_firmware |
| microsoft | surface_laptop_4_1959_firmware |
| microsoft | surface_laptop_4_1978_firmware |
| microsoft | surface_laptop_4_1979_firmware |
| microsoft | surface_laptop_go_1943_firmware |
| microsoft | surface_laptop_go_2_2013_firmware |
| microsoft | surface_laptop_go_3_2013_firmware |
| microsoft | surface_pro_7\+_1960_firmware |
| microsoft | surface_pro_7\+_with_lte_advanced_1961_firmware |
| microsoft | surface_pro_8_1983_firmware |
| microsoft | surface_pro_8_for_business_1983_firmware |
| microsoft | surface_pro_8_for_business_with_lte_advanced_1982_firmware |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.