Impact
The vulnerability is a protection mechanism failure in Windows BitLocker that allows an unauthorized attacker to bypass a security feature through a physical attack. The flaw lets the attacker circumvent BitLocker encryption controls, potentially accessing encrypted data and thereby violating confidentiality. The weakness is identified as CWE-693.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 are affected.
Risk and Exploitability
The CVSS score of 5.3 categorizes it as moderate severity. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV. It requires physical access to the system, limiting exploitation to scenarios where an attacker can tamper with the device or its storage media. Consequently, the risk is moderate to high in environments with weak physical security.
OpenCVE Enrichment