Executive brief
A vulnerability in Microsoft's Azure and Device Health Attestation services could allow an attacker with physical access to a device to spoof its security health status. These services are used to verify that a computer's hardware and software are in a trusted state before allowing access to sensitive corporate resources. While the risk is low because it requires physical access and high-level administrative privileges, a successful exploit could allow a compromised device to appear secure to the network.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Microsoft Azure Attestation and Device Health Attestation services. The flaw allows an attacker to perform spoofing by providing crafted input that the services fail to properly validate. To exploit this, an attacker must have physical access to the target hardware and possess high-level administrative privileges (PR:H). Successful exploitation allows the attacker to bypass integrity checks, potentially misrepresenting the security posture of the device to attestation providers. Microsoft has addressed this issue in their June 2026 security updates.
Affected products
- Microsoft Azure Attestation
- Microsoft Device Health Attestation Service
Timeline
- 2026-06-09: disclosed: Initial publication by Microsoft and NVD.
- 2026-06-09: advisory: Microsoft released security update guide for CVE-2026-45642.