Executive brief
Microsoft's Azure Attestation and Device Health Attestation services are cloud-based components used to verify the integrity and identity of devices and systems in enterprise environments. An out-of-bounds read vulnerability allows an attacker to read sensitive information from these services over the network, potentially exposing attestation data, credentials, or other confidential details that could be used to compromise device trust or gain unauthorized access to protected systems.
Technical details
The vulnerability is an out-of-bounds read in the Azure Attestation service and Device Health Attestation Service that permits unauthorized information disclosure. The flaw allows a network-based attacker to read memory beyond intended boundaries, potentially accessing sensitive attestation responses, cryptographic material, or authentication tokens. No authentication appears to be required for exploitation. An attacker can leverage this to extract confidential information transmitted by or stored within the attestation services, compromising the integrity of device attestation operations.
Affected products
- Microsoft Azure Attestation
- Microsoft Device Health Attestation Service
Timeline
- 2026-09-08: disclosed