Executive brief
A security bypass vulnerability exists in Microsoft BitLocker, the full-disk encryption feature used to protect data on Windows devices. An attacker with physical access to a powered-off or locked device could potentially bypass encryption protections to access sensitive information. This could lead to the unauthorized exposure of corporate data if a laptop or workstation is lost or stolen.
Technical details
A protection mechanism failure (CWE-693) exists in Microsoft BitLocker. The vulnerability allows an attacker with physical access to the target hardware to bypass security features intended to restrict access to encrypted data. According to the CVSS vector, the attack requires no prior privileges or user interaction and has a high impact on data confidentiality. This is likely a bypass of the pre-boot authentication or the encryption key protection mechanism. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Windows BitLocker
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory