Junglewise Threat Intelligence

CVE-2026-54120: Microsoft Surface Management Services remote code execution

CVE-2026-54120 · Severity: critical · CVSS 9.9 · Published 2026-07-24

Vendors: Microsoft.

Executive brief

A critical vulnerability exists in Microsoft Surface Management Services that could allow an authorized user to take control of the system. By sending specially crafted data over the network, an attacker can bypass security checks to run unauthorized commands. This could lead to a total compromise of the affected device, including the theft of sensitive data or a complete service shutdown.

Technical details

A remote code execution vulnerability exists in Microsoft Surface Management Services due to improper input validation (CWE-20). An attacker with low-privileged credentials can exploit this flaw by sending malicious requests over the network to the affected service. Because the vulnerability has a 'Changed' scope (S:C) in the CVSS metric, an exploit could allow the attacker to impact components beyond the immediate security scope of the management service. Successful exploitation grants the attacker full confidentiality, integrity, and availability impact on the target system.

Affected products

  • Microsoft Surface Management Services All versions

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References