CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-45642: Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability

lowCVSS 3.9CVE-2026-45642
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.

CSIRTS triage

What
Improper input validation allows an authorized attacker to perform spoofing with a physical attack.
Who is affected
Deployments of Microsoft Azure Attestation service and Device Health Attestation Service.
Urgency
Remediation is low urgency due to the low severity and lack of exploitation.
Action
No immediate action required.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Azure Attestation service

Get an email when a new Azure Attestation service advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
low — CVSS 3.9
Published
2026-06-09
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45642

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-45642coverage & exploitation statusNVD · CVE.org

More from Microsoft Security Response Center