PT-2024-4733 · Microsoft · Windows Bitlocker+1

Bill Demirkapi

·

Published

2024-07-09

·

Updated

2024-08-26

·

CVE-2024-38058

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Windows BitLocker (affected versions not specified)
Description: The issue is related to a security feature bypass vulnerability in the BitLocker data protection function of Windows operating systems. This vulnerability can be exploited by an attacker with physical access to bypass existing security restrictions and gain access to encrypted data. Microsoft has disabled a fix for this issue due to firmware incompatibility problems that caused devices to enter BitLocker recovery mode. As a result, customers are advised to apply manual mitigations.
Recommendations: To mitigate this issue, apply the manual mitigations advised by Microsoft, which require restarting the impacted device eight times. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

BDU:2024-05253
CVE-2024-38058

Affected Products

Windows
Windows Bitlocker