Impact
The vulnerability is an improper access control issue (CWE‑284) in the Windows BitLocker implementation. It enables an authorized local attacker to bypass a BitLocker security feature.
Affected Systems
Affected systems include Microsoft Windows 10 released versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 signals a high‑severity vulnerability that requires local authorized access. The EPSS score of <1% indicates a low likelihood that the flaw has been exploited in the wild, and the vulnerability is not included in CISA’s KEV catalog. Based on the description, the likely attack vector is a local authorized attacker; an unauthorized remote attacker cannot exploit the flaw without first becoming authorized on the affected system.
OpenCVE Enrichment