CVE-2020-0702High

Surface Hub Security Feature Bypass Vulnerability

Published
February 11, 2020
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A security feature bypass vulnerability exists in Surface Hub when prompting for credentials. Successful exploitation of the vulnerability could allow an attacker to access settings which are restricted to Administrators. To exploit the vulnerability, an attacker would need to have physical access to a Surface Hub. The update addresses the vulnerability by correcting how credentials are validated when accessing restricted settings.

🎯 Affected products1

  • Microsoft Surface Hub

✅ Remediation

KB4537765 (Security Update)

🔗 References (2)