Impact
The vulnerability is a protection mechanism failure in Windows BitLocker that permits an attacker with physical access to bypass a security feature, potentially allowing them to read or modify data protected by BitLocker encryption without proper authentication. This flaw is classified as CWE‑693, indicating a failure to enforce a protection mechanism intended to preserve confidentiality and integrity.
Affected Systems
The flaw affects Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 24H2, 25H2 and 26H1; and Windows Server 2016, 2019, 2022 and 2025, including both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 6.1 denotes moderate severity, while the EPSS score of less than 1% implies a low probability of exploitation. The vulnerability requires a physical attack; no remote exploitation path is documented. Because it undermines the integrity of the BitLocker protection, the risk to confidentiality is significant for systems that rely solely on BitLocker. The flaw is not listed in the CISA KEV catalog, indicating no known active exploitation campaigns.
OpenCVE Enrichment