CVE-2026-71331: Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
Other sources
Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33296Patch KB5120233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.9115Patch KB5120238 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5499Fixed in 10.0.20348.5440Patch KB5120229
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71331?
CVE-2026-71331 has a severity score of 8.1, indicating it is a high-risk vulnerability.
How do I fix CVE-2026-71331?
To mitigate CVE-2026-71331, users should apply the latest security updates provided by Microsoft for the affected software versions.
What systems are affected by CVE-2026-71331?
CVE-2026-71331 impacts Microsoft Windows Server 2025, 2019, 2022, Windows 10, Microsoft Azure Attestation service, and Device Health Attestation Service.
What type of vulnerability is CVE-2026-71331?
CVE-2026-71331 is classified as an Integer Overflow vulnerability, which allows unauthorized remote code execution.
What is the potential impact of CVE-2026-71331?
If exploited, CVE-2026-71331 could allow an unauthorized attacker to execute arbitrary code on affected systems via the network.