← back
CVE-2025-55333

Windows BitLocker Security Feature Bypass Vulnerability

CVSS 6.1 MEDIUMEPSS 0.8%CWE-1023
In short

Windows BitLocker, a disk encryption feature, has a flaw that allows someone with physical access to a computer to bypass its security protections. This means an attacker could potentially access encrypted data without the proper password.

Technical detail

A logic error in BitLocker's comparison mechanism (CWE-1023: Incomplete Comparison) permits an attacker with physical device access to circumvent security validation checks. Exploitation requires direct physical interaction with the target system; successful bypass may lead to unauthorized access to encrypted disk contents.

Summary generated and translated by AI from the official description.
Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →