PT-2025-27789 · Microsoft · Windows+1

Published

2025-07-03

·

Updated

2025-07-03

·

CVE-2025-27460

CVSS v3.1

7.6

High

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Windows (affected versions not specified)
Description: The issue concerns the lack of full volume encryption on device hard drives, such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating system, bypassing the Windows login and enabling them to read from and write to all files on the hard drives.
Recommendations: For Windows, enable full volume encryption using a feature like BitLocker to protect data on the hard drives. As a temporary workaround, consider using alternative encryption methods or physically securing devices to minimize the risk of unauthorized access.

Fix

Inadequate Encryption Strength

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-10434
CVE-2025-27460

Affected Products

Bitlocker
Windows