Impact
The vulnerability is an improper access control flaw (CWE‑284) in Windows BitLocker that allows an authorized attacker to bypass the security feature locally. The local bypass could allow the attacker to access data that normally requires pre‑boot authentication, thereby compromising the confidentiality of encrypted volumes.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versionsH2, 25H2, 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core editions.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability that requires local access, meaning the attacker must already be logged on and the EPSS score of <1% signals a low exploitation likelihood in the wild, and the vulnerability is not currently listed in CISA’s KEV catalog, suggesting no widespread automated attacks yet. Nevertheless, because it permits local bypass of encryption on any affected BitLocker volume, it remains a significant risk for systems storing sensitive data or subject to regulatory compliance.
OpenCVE Enrichment