Impact
An out‑of‑bounds read flaw in Windows BitLocker can be exploited by an attacker with authorization on the network to elevate privileges. The flaw does not allow arbitrary code execution but can lead to higher‑privilege access to protected resources, potentially allowing further compromise.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2 through 26H1 (including ARM64 and x64); Microsoft Windows Server from 2012 (including R2 and Server Core), 2016, 2019, 2022, and 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 8 indicates medium‑to‑high severity. EPSS data is unavailable, so the current exploitation probability is unclear, and the vulnerability is not listed in CISA KEV. The likely attack path requires a network‑connected asset that the attacker can reach with some level of authorization; it is not a remote code execution flaw. Given the moderate CVSS score and absence of exploitation guidance, the risk is significant for organizations that have unpatched BitLocker deployments and are exposed to potential insider or medium‑privilege adversaries.
OpenCVE Enrichment