Vulnerability · NVD
CVE-2026-66802
HIGH 8.1
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
Attack vector : Network
No privileges required
No user interaction
Show raw CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Server 2025 Fixed in 10.0.26100.33296
- Windows Server 2022 Fixed in 10.0.20348.5499
- Windows Server 2019 Fixed in 10.0.17763.9115
- Windows 11 26H1 · 2026-H1 Fixed in 10.0.28000.2704
- Windows 10 1809 · 2018-09 Fixed in 10.0.17763.9115