CVE-2026-66802: Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
Other sources
Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.9115Patch KB5120238 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5499Fixed in 10.0.20348.5440Patch KB5120229 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33296Fixed in 10.0.26100.33222Patch KB5120228 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2704Patch KB5121000
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66802?
CVE-2026-66802 has a high severity rating of 8.1.
How do I fix CVE-2026-66802?
To fix CVE-2026-66802, apply the latest security updates released by Microsoft for affected Windows Server and Windows operating systems.
What type of vulnerability is CVE-2026-66802?
CVE-2026-66802 is a Remote Code Execution vulnerability caused by a race condition in the Device Health Attestation service.
Which systems are affected by CVE-2026-66802?
CVE-2026-66802 affects Microsoft Windows Server 2019, 2022, 2025, Windows 10, Windows 11, and the Azure Attestation service.
What can an attacker achieve by exploiting CVE-2026-66802?
An attacker exploiting CVE-2026-66802 can execute arbitrary code over a network, potentially compromising the affected system.