Overview
What is CVE-2026-45642?
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
Vulnerability intelligence
CVE-2026-45642 and is rated Low severity with a CVSS score of 3.9. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.