CVE-2020-0702: Surface Hub Security Feature Bypass Vulnerability

Overview

Severity
N/A
Category
Security Feature Bypass
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Feb
Released
2020-02-11
EPSS Score
0.23% (percentile: 45.6%)

Description

A security feature bypass vulnerability exists in Surface Hub when prompting for credentials. Successful exploitation of the vulnerability could allow an attacker to access settings which are restricted to Administrators. To exploit the vulnerability, an attacker would need to have physical access to a Surface Hub. The update addresses the vulnerability by correcting how credentials are validated when accessing restricted settings.

Affected Products (1)

Device

  • Microsoft Surface Hub

Security Updates (1)

Revision History

  • 2020-02-11: Information published.