Impact
Concurrent execution of shared resource operations within the Windows Device Health Attestation (DHA) service contains a race condition (CWE‑362) and an improper use‑after‑free (CWE‑416) due to improper synchronization, enabling an unauthorized attacker to execute code over a network. Successful exploitation would grant the attacker code‑execution privileges, potentially compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
Microsoft Windows 10 Version 1809, Windows 11 version 26H1, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, and Windows Server 2025 (Server Core installation) are all impacted. The flaw applies to both 32‑bit and 64‑bit builds of the operating systems listed.
Risk and Exploitability
The CVSS score of 8.1 reflects high severity, and the EPSS score of < 1% indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed field‑deployed exploits publicly. Attackers would need network‑level access to the Device Health Attestation service and sufficient privileged access to trigger the race condition; the flaw is remotely exploitable via crafted network traffic. Based on the description, the likely attack vector is inferred to be network‑based.
OpenCVE Enrichment