PT-2025-27789 · Microsoft · Windows+1
Published
2025-07-03
·
Updated
2025-07-03
·
CVE-2025-27460
CVSS v3.1
7.6
High
| Vector | AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Windows (affected versions not specified)
Description:
The issue concerns the lack of full volume encryption on device hard drives, such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating system, bypassing the Windows login and enabling them to read from and write to all files on the hard drives.
Recommendations:
For Windows, enable full volume encryption using a feature like BitLocker to protect data on the hard drives.
As a temporary workaround, consider using alternative encryption methods or physically securing devices to minimize the risk of unauthorized access.
Fix
Inadequate Encryption Strength
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bitlocker
Windows