Impact
An out-of-bounds read in Microsoft Azure Attestation service and Device Health Attestation Service can allow an attacker to read memory and disclose data over a network. The vulnerability does not enable code execution or privilege escalation, but reveals sensitive information that could aid reconnaissance or further attacks.
Affected Systems
Microsoft Windows 10 Version 1809 and Windows Server 2019 (including Server Core), Windows Server 2022, Windows Server 2025 (including Server Core) are affected. No additional versions or vendors are listed.
Risk and Exploitability
The CVSS score of 7.5 reflects high severity. The EPSS score of 1% indicates a low but non‑zero exploitation probability, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a network‑based unauthorized session that triggers the out‑of‑bounds read through the DHA component. No Privilege Escalation, but the disclosed data could aid attackers in subsequent operations.
OpenCVE Enrichment