Windows Device Health Attestation (DHA) Remote Code Execution VulnerabilityVendor advisorypatch
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66802 CVE-2026-66802
HIGH
Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Record summary
CVE-2026-66802 has a selected CVSS score of 8.1 (high).
Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
Description source: GitHub Advisory
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List
Affected products and versions
7| Product | Source | Version range | Status |
|---|---|---|---|
Windows 10 Version 1809Browse Microsoft / Windows 10 Version 1809 | CVE List | 10.0.17763.0 to < 10.0.17763.9115 | affected |
Windows 11 version 26H1Browse Microsoft / Windows 11 version 26H1 | CVE List | 10.0.28000.0 to < 10.0.28000.2704 | affected |
Windows Server 2019Browse Microsoft / Windows Server 2019 | CVE List | 10.0.17763.0 to < 10.0.17763.9115 | affected |
Windows Server 2019 (Server Core installation)Browse Microsoft / Windows Server 2019 (Server Core installation) | CVE List | 10.0.17763.0 to < 10.0.17763.9115 | affected |
Windows Server 2022Browse Microsoft / Windows Server 2022 | CVE List | 10.0.20348.0 to < 10.0.20348.5499 | affected |
Windows Server 2025Browse Microsoft / Windows Server 2025 | CVE List | 10.0.26100.0 to < 10.0.26100.33296 | affected |
Windows Server 2025 (Server Core installation)Browse Microsoft / Windows Server 2025 (Server Core installation) | CVE List | 10.0.26100.0 to < 10.0.26100.33296 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-66802