Описание
Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
FAQ
How do I protect myself from this vulnerability?
Microsoft has already deployed a service-side fix for this vulnerability in Azure Attestation. No customer patching or update installation is required.
To ensure you remain protected, follow the guidance below:
Use the latest supported attestation policy
- No action is required if you are already using the current recommended policy version (1.2) for Azure Attestation.
Do not rely on certain attestation events for security decisions
- Customers should not use the following events for security assertions in attestation policies:
These events can no longer be considered trustworthy signals for attestation evaluation.
Adjust existing policies if needed
- If your current attestation policy relies on these events for security enforcement, update it to remove them.
- You may still reference these events for diagnostic or informational purposes only, but they should not be used to make trust decisions.
Continue monitoring via supported claims
- If needed, the above events are still available in the allEvents claim.
- However, Microsoft does not guarantee the integrity or trustworthiness of data within these events.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Windows Server 2012 | ||
| Windows Server 2012 (Server Core installation) | ||
| Windows Server 2012 R2 | ||
| Windows Server 2012 R2 (Server Core installation) | ||
| Windows Server 2016 | ||
| Windows 10 Version 1607 for 32-bit Systems | ||
| Windows 10 Version 1607 for x64-based Systems | ||
| Windows Server 2016 (Server Core installation) | ||
| Windows 10 Version 1809 for 32-bit Systems | ||
| Windows 10 Version 1809 for x64-based Systems |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
3.9 Low
CVSS3
Связанные уязвимости
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
Уязвимость служб Microsoft Azure Attestation Service и Device Health Attestation Service операционных систем Windows, позволяющая нарушителю проводить спуфинг-атаки
EPSS
3.9 Low
CVSS3