CVE-2026-45642: Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
Other sources
Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9234Patch KB5094122 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23228Patch KB5094041 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32995Patch KB5094125 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.26132Patch KB5094042 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2269Patch KB5095051 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8655Patch KB5094126 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.7219Patch KB5093998 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8655Patch KB5094126 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7417Patch KB5094127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7417Patch KB5094127 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8880Patch KB5094123 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5256Patch KB5094128
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45642?
The severity of CVE-2026-45642 is rated low with a score of 3.9.
What systems are affected by CVE-2026-45642?
CVE-2026-45642 affects Microsoft Windows 10, Windows 11, and various versions of Windows Server including 2012, 2016, 2019, 2022, and 2025.
How can an attacker exploit CVE-2026-45642?
An attacker can exploit CVE-2026-45642 by performing a spoofing attack through improper input validation during a physical attack.
What is the nature of the vulnerability in CVE-2026-45642?
CVE-2026-45642 is a spoofing vulnerability resulting from improper input validation within the Microsoft Azure Attestation service and Device Health Attestation Service.
What remediation steps should be taken for CVE-2026-45642?
To remediate CVE-2026-45642, ensure that all software is updated to the latest versions provided by Microsoft.