Impact
The vulnerability involves missing authentication in Windows BitLocker, enabling an attacker with physical access to bypass encryption controls through a critical function. This flaw allows the attacker to read, modify, or delete data on encrypted volumes without performing traditional privilege escalation, directly compromising data confidentiality and integrity on affected systems.
Affected Systems
Affected systems include Microsoft Windows 10 releases from version 1607, 1809, 21 H2, and 22 H2; Microsoft Windows 11 releases from 23 H2 through 26 H1; and Microsoft Windows Server editions from 2012 R2 through 2025, including Server Core installations. All major processor architectures (x86, x64, ARM64) are impacted.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, while the EPSS score of 5 % reflects a moderate likelihood of exploitation. The vulnerability requires physical access; remote exploitation is unlikely. It is not listed in the CISA KEV catalog, meaning no known active exploits in the wild. If exploited, an attacker could read or alter data protected by BitLocker, but the flaw does not provide a pathway to elevate privileges beyond the local user context.
OpenCVE Enrichment