CVE-2026-66802 – Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability

CVSS 8.1 IMPORTANT Critical - Same Day Deployment

“A specially crafted network packet could turn a race condition into remote code execution, with no authentication or user action required.”

CVE-2026-66802 is a critical remote code execution vulnerability affecting Microsoft Azure Attestation service and Device Health Attestation Service. Improper synchronization of a shared resource can create a race condition leading to a use-after-free condition. An unauthenticated remote attacker who successfully wins the race condition could execute code on the target system.

CVSS Score: 8.1.

SEVERITY: Critical.

THREAT:
The vulnerability is remotely reachable over the network and can affect confidentiality, integrity, and availability at a high level. Exploitation requires high attack complexity because an attacker must successfully win a race condition, but no privileges, authentication, or user interaction are required.

EXPLOITS:
This vulnerability is not publicly disclosed and is not reported as exploited. Exploit code maturity is Unproven, and exploitation is assessed as Less Likely. The existence of public exploit code, zero-day exploitation, or proof-of-concept code cannot be confirmed.

TECHNICAL SUMMARY:
The vulnerability results from concurrent execution using a shared resource without proper synchronization, identified as a race condition and use-after-free weakness (CWE-362 and CWE-416). An unauthenticated attacker could send a specially crafted packet to an affected service over the network. Successful exploitation depends on winning the race condition and could result in arbitrary code execution on the target system. The CVSS metrics indicate network-based attack access, high attack complexity, no required privileges, no user interaction, unchanged scope, and high confidentiality, integrity, and availability impacts.

EXPLOITABILITY:
Affected products include Windows 10 Version 1809 (32-bit and x64), Windows 11 Version 26H1 (ARM64 and x64), Windows Server 2019, Windows Server 2022, Windows Server 2025, and the listed Server Core installations. An unauthenticated attacker could exploit the issue remotely with a specially crafted network packet but must successfully win a race condition.

BUSINESS IMPACT:
Successful exploitation could allow unauthorized remote code execution and cause serious compromise of affected systems. Because confidentiality, integrity, and availability impacts are all rated High, successful attacks could expose sensitive information, alter system resources, or disrupt affected services. “No login and no user click means the vulnerable service itself is the attack surface.”

WORKAROUND:
No mitigations or workarounds are specified. An official fix is identified as the remediation.

URGENCY:
This vulnerability is rated Critical and permits network-based remote code execution without privileges or user interaction. Although exploitation is assessed as Less Likely and is not reported as occurring, affected systems should be prioritized for deployment of the official fix because successful exploitation could have high confidentiality, integrity, and availability impacts.

Key Details

Affected Product
Microsoft Windows 10 1809
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
CWE Classification
CWE-362
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.