CVE-2026-69443: Windows Device Health Attestation (DHA) Information Disclosure Vulnerability
Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network.
Other sources
Windows Device Health Attestation (DHA) Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33438Patch KB5122871 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.9245Patch KB5122876 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5622Patch KB5122882
Event History
Frequently Asked Questions
Which systems are identified as affected?
The listed affected products are Microsoft Windows Server 2025, Windows Server 2022, Windows Server 2019, and Windows 10.
Does exploitation require authentication or user interaction?
No. The supplied vector indicates network access, low attack complexity, no privileges required, and no user interaction.
What is the expected impact of successful exploitation?
Successful exploitation can disclose information. The supplied impact vector indicates high confidentiality impact, with no integrity or availability impact.