Windows Device Health Attestation (DHA) Remote Code Execution VulnerabilityVendor advisorypatch
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71331 CVE-2026-71331
HIGH
Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Record summary
CVE-2026-71331 has a selected CVSS score of 8.1 (high).
Description
Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
Description source: GitHub Advisory
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 10, 2026 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
Windows 10 Version 1809Browse Microsoft / Windows 10 Version 1809 | CVE List | 10.0.17763.0 to < 10.0.17763.9115 | affected |
Windows Server 2019Browse Microsoft / Windows Server 2019 | CVE List | 10.0.17763.0 to < 10.0.17763.9115 | affected |
Windows Server 2019 (Server Core installation)Browse Microsoft / Windows Server 2019 (Server Core installation) | CVE List | 10.0.17763.0 to < 10.0.17763.9115 | affected |
Windows Server 2022Browse Microsoft / Windows Server 2022 | CVE List | 10.0.20348.0 to < 10.0.20348.5499 | affected |
Windows Server 2025Browse Microsoft / Windows Server 2025 | CVE List | 10.0.26100.0 to < 10.0.26100.33296 | affected |
Windows Server 2025 (Server Core installation)Browse Microsoft / Windows Server 2025 (Server Core installation) | CVE List | 10.0.26100.0 to < 10.0.26100.33296 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-71331