Microsoft has released fixes for CVE-2026-71331, Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability, a Critical network-exposed flaw that can let an unauthenticated attacker execute code on an affected target system by sending a specially crafted packet. Microsoft’s Security Response Center rates it 8.1 on the CVSS base scale, with a 7.1 temporal score, and says customer action is required.

The patching priority is clear even though Microsoft assesses exploitation as less likely. The vulnerability requires no credentials and no user interaction, and its CVSS vector assigns high impacts to confidentiality, integrity, and availability once exploitation succeeds. Administrators responsible for Windows Server 2019, Windows Server 2022, Windows Server 2025, or retained Windows 10 Version 1809 DHA deployments should identify the applicable servicing build and install the corresponding update.

Microsoft’s advisory identifies the issue as an integer overflow or wraparound in Windows Device Health Attestation (DHA) that allows an unauthorized attacker to execute code over a network. The weakness classifications are CWE-122 and CWE-190.

Abstract illustration of connected devices separated by a protected security boundary.Microsoft’s assessment of CVE-2026-71331​

Microsoft lists the severity as Critical and provides this complete score vector:

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

In operational terms, the vector describes a network attack with no privileges and no user interaction required. Microsoft says an unauthenticated attacker could send a specially crafted packet to an affected service over the network; successful exploitation could allow code execution on the target system.

The advisory’s high attack-complexity rating is material, but it should not be read as a network control. Microsoft says successful exploitation requires a deep understanding of the system and is not guaranteed, depending on a combination of environmental conditions, system configuration, and possible additional security measures. Those conditions lower the expected reliability of an exploit; they do not change the consequences when an attacker does reach code execution.

Microsoft’s official assessment records the following status fields:

  • Publicly disclosed: No
  • Exploited: No
  • Customer action required: Yes

Microsoft’s exploitation assessment is Exploitation Less Likely. The record therefore supports routine but prompt patch deployment through the organization’s normal change process, with priority given to exposed DHA roles and systems whose attestation services are reachable across network boundaries.


DHA and Azure Attestation are named in the advisory record​

The formal CVE title is “Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability.” Microsoft describes the specific defect this way: “Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.”

The MSRC material also contains an advisory fact headed “Microsoft Azure Attestation service and Device Health Attestation Service Remote Code Execution Vulnerability.” In that statement, Microsoft says integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.

For administrators, the important boundary is the supplied affected-product list: it contains Windows Device Health Attestation-related Windows client and server products, including Server Core installations. The record does not make this a generic Windows update issue across every supported Windows release; it identifies a defined set of Windows 10 Version 1809 and Windows Server versions, with distinct KB and build targets.

This is also why build verification should follow installation. A successful update deployment report is useful, but the advisory supplies explicit fixed-build values. Comparing the running build to Microsoft’s stated target provides a direct remediation check, particularly where update rings, offline servicing, or delayed restart policies may leave a machine below the fixed build after a KB has been approved.

Windows 10 Version 1809 and Windows Server 2019 fixes​

Microsoft assigns KB5120238 and fixed build 10.0.17763.9121 to four listed products:

  • For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5120238 to reach fixed build 10.0.17763.9121.
  • For Windows 10 Version 1809 for x64-based Systems, install KB5120238 to reach fixed build 10.0.17763.9121.
  • For Windows Server 2019 (Server Core installation) (x64), install KB5120238 to reach fixed build 10.0.17763.9121.
  • For Windows Server 2019 (x64), install KB5120238 to reach fixed build 10.0.17763.9121.

The shared build number is useful for mixed Server 2019 estates: Server Core and the full Windows Server 2019 installation have the same stated fixed build for this CVE. Windows 10 Version 1809 x86 and x64 likewise converge on the same target build, so compliance reporting can use 10.0.17763.9121 as the practical post-update threshold for the affected products listed above.

The key administrative point is to avoid treating “Windows Server 2019” as a sufficient compliance result without checking the servicing level. Microsoft’s remediation attaches the security fix to KB5120238 and the precise 10.0.17763.9121 build, rather than to the operating-system label alone.


Windows Server 2022 has two listed KB-to-build paths​

Microsoft lists two KB and fixed-build combinations for each affected Windows Server 2022 installation type:

  • For Windows Server 2022 (Server Core installation) (x64), install KB5120229 to reach fixed build 10.0.20348.5440; install KB5120242 to reach fixed build 10.0.20348.5499.
  • For Windows Server 2022 (x64), install KB5120229 to reach fixed build 10.0.20348.5440; install KB5120242 to reach fixed build 10.0.20348.5499.

This is the remediation detail most likely to complicate automated reporting. Microsoft’s record maps both KB5120229 and KB5120242 to Windows Server 2022, each with its own fixed build. An inventory rule that recognizes only one of the two KB identifiers, or expects only one build number, can misclassify patched systems.

For Windows Server 2022 (Server Core installation) (x64) and Windows Server 2022 (x64), the approved remediation values are therefore KB5120229 with build 10.0.20348.5440 and KB5120242 with build 10.0.20348.5499. Patch-management teams should preserve that two-path mapping when creating detection logic, maintenance-window evidence, and vulnerability exceptions.

Windows Server 2025 remediation​

Microsoft maps CVE-2026-71331 on Windows Server 2025 to KB5120233 and fixed build 10.0.26100.33296:

  • For Windows Server 2025 (Server Core installation) (x64), install KB5120233 to reach fixed build 10.0.26100.33296.
  • For Windows Server 2025 (x64), install KB5120233 to reach fixed build 10.0.26100.33296.

As with Server 2019, the Server Core and full-installation variants use the same KB and fixed build. That simplifies validation, but the Server Core designation still belongs in deployment records because Microsoft explicitly lists it as an affected product.

The complete Microsoft remediation is: For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5120238 to reach fixed build 10.0.17763.9121. For Windows 10 Version 1809 for x64-based Systems, install KB5120238 to reach fixed build 10.0.17763.9121. For Windows Server 2019 (Server Core installation) (x64), install KB5120238 to reach fixed build 10.0.17763.9121. For Windows Server 2019 (x64), install KB5120238 to reach fixed build 10.0.17763.9121. For Windows Server 2022 (Server Core installation) (x64), install KB5120229 to reach fixed build 10.0.20348.5440; install KB5120242 to reach fixed build 10.0.20348.5499. For Windows Server 2022 (x64), install KB5120229 to reach fixed build 10.0.20348.5440; install KB5120242 to reach fixed build 10.0.20348.5499. For Windows Server 2025 (Server Core installation) (x64), install KB5120233 to reach fixed build 10.0.26100.33296. For Windows Server 2025 (x64), install KB5120233 to reach fixed build 10.0.26100.33296.

For this CVE, the defensible closure condition is installation of the applicable Microsoft update and verification that the affected machine has reached its stated fixed build.