Connect with us

NEWS

Call of Duty’s Azure Check Now Splits the PC Queue

Microsoft patched the Azure Attestation spoof behind a Ricochet bypass scare, but Black Ops 7 still splits PC lobbies on that check.

Published

on

Activision told players on June 10, 2026 that Microsoft had already patched the Azure Attestation spoof treated as a Call of Duty Ricochet bypass. Nick Peterson, an anti-cheat engineer at Riot Games, had posted CVE-2026-45642 a day earlier, with Secure Boot spoofed ON from a bootkit.

Season 4 still uses that Microsoft check as a matchmaking gate. PCs that fail it are kept out of the main pool, which is why a cloud bug now reads as a Call of Duty incident.

The Bypass Clip Was a Patched Microsoft Bug

Peterson wrote that some Microsoft Azure Attestation metrics had been open to spoofing and would accept attacker-controlled measurements. In the clip, Secure Boot showed as ON under a malicious bootkit. He pointed at CVE-2026-45642, which Microsoft published on June 9, 2026.

Up until just recently, some metrics of Microsoft Azure Attestation were completely vulnerable to spoofing in some circumstances, and would accept attacker controlled measurements. SecureBoot in this case, spoofed as ON from a malicious bootkit.

Nick Peterson, anti-cheat engineer at Riot Games, on X

https://x.com/nickeverdox/status/2064441584754827379

Microsoft’s advisory describes improper input validation in Azure Attestation and Device Health Attestation that lets an authorized attacker spoof results with a physical attack. The CVSS 3.1 score is 3.9, with vector AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N, CWE-20, no public exploit, and an assessment of exploitation less likely. Integrity is the only impact listed. Confidentiality and availability are none.

Microsoft also said it had already shipped a service-side fix for the spoof, with no customer patch required if a tenant is on attestation policy version 1.2. The same note tells customers not to treat EV_EFI_VARIABLE_AUTHORITY or EV_EFI_BOOT_SERVICES_APPLICATION as trust signals. Microsoft credited Peterson, with Riot Games, in the acknowledgement line. The hole was an Azure attestation bug in Ricochet’s new cloud check, not a fresh crack in the game client.

How Remote Attestation Replaced Local Checks

Team RICOCHET’s Season 4 note is blunt about why it moved the check off the PC. Some games rely on local tests that a tampered machine can answer with a false all-clear. Remote attestation sends those measurements to Microsoft’s servers instead, which is the point of using Azure Attestation rather than a client-side flag.

Microsoft describes the product as a service for remotely verifying platform trustworthiness and the binaries running on it, including TPM-backed machines. A PC proves a trusted boot path. Ricochet then treats that proof as a ticket into the main Call of Duty pool. On February 2, 2026, Team RICOCHET said Ranked Play would get cloud-based attestation for Ranked Play first, on top of the TPM 2.0 and Secure Boot rules already in Black Ops 7.

That is a different bet from kernel scans alone. The game is no longer asking only whether a cheat process is visible after launch. It is asking Microsoft whether the boot chain looks intact before the lobby fills. When that service takes a CVE, Call of Duty inherits the headline, even if the patch never touches a game file.

Failed Attestation Leaves Only Nuketown and Casual

Season 4, which Team RICOCHET detailed on June 4, 2026, five days before the CVE, turned the check into a playlist lock. Players who fail Microsoft Azure Attestation go into a separate pool. Team RICOCHET said that pool is small, so it keeps only a short set of modes to hold matchmaking together.

On Black Ops 7 that leftover mode is Nuketown 24/7. On Warzone it is Battle Royale Casual. Failed PCs also cannot queue with machines that passed, and they cannot queue with consoles. A party fails the whole group if one member fails, which is how a single old firmware build can bench four people.

THE SEASON 4 ATTESTATION SPLIT

Check result Black Ops 7 access Warzone access Who you can play with
Passed MAA All playlists All playlists Compliant PCs and consoles
Failed MAA Nuketown 24/7 only Battle Royale Casual only Other failed PCs only

Team RICOCHET’s own wording puts those leftover lists at Nuketown 24/7 and Battle Royale Casual. The design is not a shadow ban in the old sense. It is an advertised second queue for machines Microsoft will not vouch for, which is why a spoof of Secure Boot looked, to a lot of players, like a golden ticket into the clean pool.

TPM 2.0, Secure Boot, and the Party Rule

Full access still hangs on two firmware switches plus a clean handshake with Azure. Team RICOCHET says a PC must have TPM 2.0 enabled and Secure Boot enabled. AMD machines running TPM software in the 3.x.0.x range can error during attestation until a BIOS or firmware update lands. The game then shows a Failed Attestation Status message and moves the account into the short playlist set.

WHAT THE CHECK ASKS FOR

  • TPM 2.0: The module must be on and ready, because remote attestation treats it as the root of the boot proof.
  • Secure Boot: UEFI must refuse untrusted boot loaders, which is the flag Peterson showed being spoofed in the CVE clip.
  • AMD 3.x.0.x firmware: Team RICOCHET says that TPM software range can fail the handshake until the board maker ships a BIOS fix.
  • The party wipe: One noncompliant PC in a squad fails attestation for everyone in that session.

Those rules started as Ranked armor in Season 2 and became a global PC filter in Season 4. Season 3, in an April 2, 2026 Team RICOCHET update, had already warned that failing TPM 2.0 and Secure Boot would soon limit playlists. The June lock was that warning with the doors actually shut.

A Riot Engineer Logged the Hole in Azure

The person who put the spoof on the timeline does not work at Activision. Peterson’s X bio lists Riot Games’ anti-cheat team, and Microsoft’s CVE note thanks him in that role. A clip from a Valorant engineer was enough to convince a slice of Call of Duty that Season 4’s new gate was already cooked.

THE ATTESTATION CALENDAR

  1. February 2, 2026: Team RICOCHET says Ranked Play will add remote Azure Attestation on top of TPM 2.0 and Secure Boot.
  2. April 2, 2026: In-game messages warn that failed attestation will start limiting playlists.
  3. June 4, 2026: Season 4 puts failed PCs in a separate pool with two leftover modes.
  4. June 9, 2026: Microsoft publishes CVE-2026-45642 and Peterson posts the Secure Boot spoof clip.
  5. June 10, 2026: The Call of Duty community team says Microsoft already fixed it and that Azure Attestation stays in Ricochet.

CallofDutyCM answered the panic thread the next morning, on June 10, 2026, and treated the report like a bug bounty packet rather than a live break of the game.

Look again and you’ll see Microsoft already fixed this. Much like our own private bug bounty, we’re grateful for those who report security vulnerabilities to our partners responsibly.

Call of Duty Community Team, on X

https://x.com/CallofDutyCM/status/2064581708259987841

The same post said Azure Attestation remains a key Ricochet piece for stopping and identifying cheaters before a match. That sentence is the dependency in plain language. Ricochet’s front door is a Microsoft service, so Microsoft’s patch calendar is now part of Call of Duty’s cheat story.

Cafe PCs and AMD Firmware Still Fail the Gate

The June clip did not turn into a documented cheater flood. What kept showing up, including in August 2026, was Failed Attestation Status on machines whose owners had already flipped the obvious switches. Internet cafe boxes with custom Windows images were one cluster. Another was AMD pre-builts whose fTPM firmware still sat in the 3.x.0.x band Team RICOCHET had flagged, including a June 5, 2026 complaint about Alienware and Dell units on version 3.92.0.5.

Some players also said Activision’s Secure Attestation Wizard marked the system compliant while ranked playlists stayed closed. That pattern fits Team RICOCHET’s own caveat: a PC can fail attestation because of hardware or firmware, not because the player cheated, and the lasting fix has to come from the board maker. A BIOS dated 2018 is not going to grow a newer TPM stack because a playlist lock appeared in Season 4.

WHAT WE KNOW

  • The patch: Microsoft says the attestation spoof is fixed on the service side and needs no Windows update from players.
  • The lock: Failed PCs are limited to Nuketown 24/7 and Warzone Battle Royale Casual and cannot mix with consoles.
  • The firmware trap: Team RICOCHET names AMD TPM software in the 3.x.0.x range as a known attestation error until BIOS is updated.

WHAT IS UNCONFIRMED

  • Live CoD abuse: Microsoft listed the CVE as not exploited and not publicly disclosed at publication, and Activision has not said the spoof was used in Black Ops 7 matches.
  • Wizard false passes: Player reports of a green Wizard result with locked playlists are not something Team RICOCHET has broken out as a measured class of failures.

The practical read is ugly in a smaller way than a public bypass. Ricochet can be working as designed and still send a cafe PC, or a two-year-old AMD firmware image, into the same leftover playlist it built for untrusted boots.

Two-Thirds of Cronus Bans Did Not Repeat

Season 4 was not only the Azure lock. Team RICOCHET said detections for scripted input devices, including Cronus Zen and XIM Matrix, were still being tightened, after Season 2 had already called those devices cheating tools even when they sit on a store shelf. Temporary bans are the current lever. The studio’s figure is that nearly two-thirds of players who got those bans came back to Black Ops 7 without the scripts.

RICOCHET’S OWN SCORECARD

  • Early beta speed: 97% of cheaters were stopped within 30 minutes of first sign-in, Team RICOCHET said after the Black Ops 7 early access weekend.
  • Match entry: Fewer than 1% of cheating attempts reached a match, and those that did were removed within minutes.
  • End of beta: Team RICOCHET called it the strongest beta result in Call of Duty history, with nearly 99% of matches cheater-free and a median detection time of three matches.
  • Device bans: Nearly two-thirds of Cronus Zen and XIM Matrix temporary bans did not return to those devices.

Those beta numbers are the studio’s, from the October 2025 test that launched toward the November 14, 2025 ship date, and they measure detections Ricochet could see. They do not measure a bootkit that had a window in Azure’s event parsing. They also do not measure a player who never cheats and still cannot leave Nuketown because Secure Boot keys will not enroll.

Team RICOCHET has already said some attestation failures are firmware, and that when players report those cases the studio takes them to manufacturers, while the actual BIOS fix still has to come from the people who shipped the board.

Frequently Asked Questions

Do Players Need a Windows Patch for CVE-2026-45642?

No. Microsoft says the fix is already live on Azure Attestation, and no customer patch or update install is required if you are on the current recommended policy version, 1.2. A Windows quality update is not the lever for this CVE; the relying service changed how it reads evidence.

What Attack Does Microsoft’s CVSS Score Describe?

The 3.9 score is a Low base with a physical attack vector, high privileges, no user interaction, unchanged scope, and high integrity impact only. Microsoft’s prose matches that vector: an authorized attacker with physical access, not a remote drive-by against every Warzone client.

Which Boot Events Did Microsoft Stop Treating as Trust Signals?

EV_EFI_VARIABLE_AUTHORITY and EV_EFI_BOOT_SERVICES_APPLICATION. Microsoft says those events can no longer be considered trustworthy for attestation evaluation, though they may still appear in the allEvents claim for diagnostics and must not be used to make trust decisions.

What Else Uses Microsoft Azure Attestation?

Microsoft documents it as a unified service for TPM attestation, Intel SGX enclaves, VBS enclaves, trusted launch monitoring on Azure VMs, and AMD SEV-SNP confidential VMs and containers. Call of Duty is a relying party on a product built for confidential computing, not a one-off game SDK.

How Do You Check TPM 2.0 and Secure Boot on Windows?

Run tpm.msc and look for a ready TPM at specification 2.0, then run msinfo32 and confirm BIOS Mode is UEFI and Secure Boot State is On. If either check fails, the remaining work is in firmware settings, not in the game menu, and AMD boards in the 3.x.0.x TPM software range still need a BIOS update after those toggles are on.

Harry edits WinAddons, an independent news site that he owns and runs, covering Windows, Xbox, Azure, Microsoft 365, Teams, OneDrive, Outlook, the software built around them and Microsoft's business. His method comes from ten years in journalism, a reporter's years followed by an editor's, and the bulk of that decade has been spent watching Microsoft ship. His reporting starts with what Microsoft publishes: release notes and KB articles read in full, build numbers checked on an installed machine, MSRC advisories and the CVE records behind them, the Azure status history, lifecycle pages, store listings in the market they apply to, and the earnings releases and filings that carry the company's numbers. Every figure is checked against its source before publication, and a public corrections policy explains how mistakes are fixed and labelled. On security stories he does not publish exploit details before a fix is available, reporting what is affected and what to do instead. Pre-release features are labelled by channel and build, and a rumour is called a rumour. Readers can reach Harry at support@winaddons.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending