Microsoft has mostly repaired a flaw in Surface hardware that allowed unprotected devices to be bricked by a single packet
ID: 1614e9b9-9930-5905-b743-0f156c9f0c3f
STIX ID: report--1614e9b9-9930-5905-b743-0f156c9f0c3f
Feed Name: The Register (Security)
Threat Score
Microsoft patched a firmware flaw in Surface devices' SAM embedded controller that could be abused by crafted SSAM ioctl commands to overwrite UEFI/Secure Boot firmware and permanently brick affected units; a researcher’s Copilot session accidentally triggered the condition. Microsoft says exploitation requires local administrator privileges and Secure Boot to be disabled, most affected devices have been updated, and the bug did not meet the bar for a CVE.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
