[WID-SEC-2026-2323] Microsoft Surface: Schwachstelle ermöglicht Erlangen von Administratorrechten CVSS Base Score 7.8 (hoch) CVSS Temporal Score 6.8 (mittel) Remoteangriff nein Datum 14.07.2026 Stand 15.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Windows Produktbeschreibung Microsoft Surface Hub ist ein digitales Whiteboard für Konferenzräume. Windows ist ein Betriebssystem von Microsoft. Produkte 14.07.2026 Microsoft Surface Hub Microsoft Windows Surface Dev Kit Microsoft Surface Hub 2S Microsoft Surface Hub 3 Angriff Angriff Ein lokaler Angreifer kann eine Schwachstelle mehreren Microsoft Surface-Produkten ausnutzen, um Administratorrechte zu erlangen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A local attacker can exploit a vulnerability in multiple Microsoft Surface products to gain administrator privileges, requiring physical access to the device. The vulnerability has a CVSS base score of 7.8 (High) and affects Microsoft Surface Hub, Surface Hub 2S, Surface Hub 3, and the Surface Dev Kit running Windows. A mitigation is available, but the article does not specify a patched version number or the exact workaround.