Surface
by Microsoft
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-54120 | Cri | 0.64 | 9.9 | 0.01 | Jul 24, 2026 | Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | ||
| CVE-2025-21194 | Hig | 0.46 | 7.1 | 0.01 | Feb 11, 2025 | Microsoft Surface Security Feature Bypass Vulnerability | ||
| CVE-2018-3639 | Med | 0.44 | 5.5 | 0.61 | May 22, 2018 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis,… | ||
| CVE-2026-48581 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. |
- risk 0.64cvss 9.9epss 0.01
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
- risk 0.46cvss 7.1epss 0.01
Microsoft Surface Security Feature Bypass Vulnerability
- risk 0.44cvss 5.5epss 0.61
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis,…
- risk 0.00cvss 7.8epss 0.00
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.