← back
CVE-2025-55333mediumCWE-1023

Windows BitLocker Security Feature Bypass Vulnerability

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.1epss 0.9%
exploitation probability
0.9%top 44% of all CVEs
observed exploitation
nono source reports it
In short

Windows BitLocker, a disk encryption feature, has a flaw that allows someone with physical access to a computer to bypass its security protections. This means an attacker could potentially access encrypted data without the proper password.

Technical detail

A logic error in BitLocker's comparison mechanism (CWE-1023: Incomplete Comparison) permits an attacker with physical device access to circumvent security validation checks. Exploitation requires direct physical interaction with the target system; successful bypass may lead to unauthorized access to encrypted disk contents.

Summary generated and translated by AI from the official description.
Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C