CVE-2026-69443
massOut-of-Bounds Read in Windows Device Health Attestation Allows Info Disclosure
CVE-2026-69443 is an out-of-bounds read (CWE-125) in the Windows Device Health Attestation (DHA) component, rated High (CVSS 3.1: 7.5) because it can be triggered over the network by an unauthenticated attacker with no user interaction. The flaw occurs when the DHA service reads beyond the bounds of a memory buffer while handling network-supplied input; the source data does not publish more granular trigger details. Successful exploitation discloses the contents of adjacent memory, making this a confidentiality-only issue with no integrity or availability impact. Any Windows installation carrying the Device Health Attestation component is affected, though the advisory data does not enumerate specific Windows versions or builds. As of the available data there is no known exploitation: no public proof-of-concept, not listed in CISA KEV, and EPSS assigns roughly a 1% chance of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69443 via Windows Update as soon as it is available, prioritizing hosts whose DHA service is reachable from untrusted networks. Check the Microsoft advisory (CNA: [email protected]) for the definitive list of affected Windows versions and build numbers, since the source data here does not enumerate them. As an interim measure, restrict network access to systems' Device Health Attestation endpoints and monitor for updated EPSS/KEV status.
| Microsoft Windows Device Health Attestation (DHA) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.