ZeroHour

CVE-2026-69443

mass

Out-of-Bounds Read in Windows Device Health Attestation Allows Info Disclosure

CVSS 3.1
7.5 high
EPSS
1%p62
Published
()
Modified
AI analysis

CVE-2026-69443 is an out-of-bounds read (CWE-125) in the Windows Device Health Attestation (DHA) component, rated High (CVSS 3.1: 7.5) because it can be triggered over the network by an unauthenticated attacker with no user interaction. The flaw occurs when the DHA service reads beyond the bounds of a memory buffer while handling network-supplied input; the source data does not publish more granular trigger details. Successful exploitation discloses the contents of adjacent memory, making this a confidentiality-only issue with no integrity or availability impact. Any Windows installation carrying the Device Health Attestation component is affected, though the advisory data does not enumerate specific Windows versions or builds. As of the available data there is no known exploitation: no public proof-of-concept, not listed in CISA KEV, and EPSS assigns roughly a 1% chance of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69443 via Windows Update as soon as it is available, prioritizing hosts whose DHA service is reachable from untrusted networks. Check the Microsoft advisory (CNA: [email protected]) for the definitive list of affected Windows versions and build numbers, since the source data here does not enumerate them. As an interim measure, restrict network access to systems' Device Health Attestation endpoints and monitor for updated EPSS/KEV status.

Affected
Microsoft Windows Device Health Attestation (DHA)
Estimated exposure
masshundreds of millions of Windows endpoints potentially carry the DHA component; the subset with the service reachable over a network is unknown — Device Health Attestation is a built-in Windows component present on the broadly deployed Windows client and server install base (order of hundreds of millions of devices), but the advisory data does not specify which versions or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network.

Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.