PT-2023-2625 · Microsoft · Windows
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows (affected versions not specified)
Description
A security-feature bypass issue exists in the Secure Boot implementation of Windows operating systems. The problem is related to errors in accessing debugging functions during the boot process, which can allow an attacker to bypass existing security restrictions. Specifically, a technique known as bitpixie can be used to trigger a boot error and read the BitLocker decryption key from memory because the bootloader fails to clear it. Attackers can bypass Secure Boot protections by downgrading the bootloader to a vulnerable version to exploit this memory reading flaw. This can be achieved without physical disassembly of the device, for example, by using a LAN cable to simulate a TFTP PXE server to deliver a downgraded bootloader.
Recommendations
Install the July 8, 2025 security updates for all supported versions of Windows.
After installing the updates, follow the steps in KB5025885 to manually enable the mitigations for Windows Boot Manager revocations.
As a temporary workaround, suspend BitLocker and disable Secure Boot in the BIOS/UEFI settings.
Fix
DoS
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows