Junglewise Threat Intelligence

CVE-2026-45642: Microsoft Azure Attestation improper input validation spoofing vulnerability

CVE-2026-45642 · Severity: low · CVSS 3.9 · Published 2026-06-09

Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft's Azure and Device Health Attestation services could allow an attacker with physical access to a device to spoof its security health status. These services are used to verify that a computer's hardware and software are in a trusted state before allowing access to sensitive corporate resources. While the risk is low because it requires physical access and high-level administrative privileges, a successful exploit could allow a compromised device to appear secure to the network.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Microsoft Azure Attestation and Device Health Attestation services. The flaw allows an attacker to perform spoofing by providing crafted input that the services fail to properly validate. To exploit this, an attacker must have physical access to the target hardware and possess high-level administrative privileges (PR:H). Successful exploitation allows the attacker to bypass integrity checks, potentially misrepresenting the security posture of the device to attestation providers. Microsoft has addressed this issue in their June 2026 security updates.

Affected products

  • Microsoft Azure Attestation
  • Microsoft Device Health Attestation Service

Timeline

  • 2026-06-09: disclosed: Initial publication by Microsoft and NVD.
  • 2026-06-09: advisory: Microsoft released security update guide for CVE-2026-45642.

References

Related threats