Impact
The vulnerability is a protection mechanism failure that allows an attacker with physical access to bypass the BitLocker security feature. By exploiting this flaw, an adversary can gain unauthorized access to data encrypted by BitLocker, compromising the confidentiality of volumes protected by the feature. The flaw does not provide remote code execution or privilege escalation beyond the local context, but it does permit disclosure of encrypted data where an attacker can intercept the device.
Affected Systems
Affected systems include all Windows 10 releases from version 1607 onward, Windows 11 releases starting with 23H2 up to 26H1, and Windows Server editions from 2012 R2 through 2025, including both full and Server Core installations. The issue spans both 32‑bit and 64‑bit builds, as well as ARM64 deployments where applicable.
Risk and Exploitability
The CVSS score of 6.8 reflects moderate severity. EPSS is not available, so the exact likelihood of exploitation is unclear; however, the vulnerability requires a physical attacker with device access, making it less likely to be exploited remotely. It is not listed in the CISA KEV catalogue, indicating no known active exploits at this time. The likely attack vector involves direct physical intrusion or a privileged pen‑test that can manipulate the BitLocker state.
OpenCVE Enrichment