• Updating your Surface

    I have several Surface devices (Surfii?) because they are one of the best traveling devices, especially if they have cellular built in and you don’t want to mess with hotel Wi-Fi, VPNs, and other roaming annoyances. But sometimes, their patching behavior is confusing. Case in point: the recent CVE-2025-21194 that patches a unique “Microsoft Surface Security Feature Bypass Vulnerability.” The theory is that it’s related to an IPv6 PixieFail vulnerability.

    As I’m reading it, I should be expecting a Surface firmware update. But as of this moment, no such release has been posted. An update was released in January, but nothing in February. The good news is that it will come down automatically via Windows update. The bad news is I’m not sure whether it’s been received already.

    When it comes to Surfaces, firmware updates do not appear to have any set release schedule. Mind you that’s true for any firmware release. When I’ve decided to move to a Windows feature release, I tend to review whether I’m missing a firmware update, especially if the Windows release is a major one. So, I’ll be reviewing the firmware status of my devices once I decide to move to 24H2. I will remind you to do likewise when it’s time.