Impact
Updated information indicates that missing authentication for a critical BitLocker function permits an unauthorized attacker to bypass a security feature through a physical attack. The flaw, classified as CWE‑306, means anyone who gains physical access can circumvent the authentication checks that normally secure encryption operations, potentially enabling decryption or alteration of data that should remain confidential.
Affected Systems
Affected systems include Microsoft Windows 10 releases from version 1607, 1809, 21 H2, and 22 H2; Microsoft Windows 11 releases from 23 H2 through 26 H1; and Microsoft Windows Server editions from 2012 R2 through 2025, including Server Core installations. All major processor architectures (x86, x64, ARM64) are impacted.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, while the EPSS score of 5 % reflects a moderate likelihood of exploitation. This flaw requires physical access, making remote attacks unlikely. The vulnerability is not listed as a CISA KEV, so there are no known active exploits in the wild. If exploited, an attacker could read or modify data protected by BitLocker, but no evidence suggests it elevates privileges beyond the local user context.
OpenCVE Enrichment