Junglewise Threat Intelligence

CVE-2026-45658: Microsoft Windows BitLocker protection mechanism failure

CVE-2026-45658 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft BitLocker. Vendors: Microsoft.

Executive brief

A security bypass vulnerability exists in Microsoft Windows BitLocker, the built-in drive encryption tool used to protect data on lost or stolen devices. An attacker with physical access to a computer could bypass encryption protections to gain unauthorized access to sensitive files. This flaw undermines the primary security purpose of BitLocker, potentially leading to full data exposure if a device is physically compromised.

Technical details

A protection mechanism failure (CWE-284) exists in Windows BitLocker's implementation of drive encryption. The vulnerability allows an attacker with physical access to the target hardware to bypass the encryption security features. According to the CVSS metrics, the attack requires low privileges and no user interaction, but is categorized under a local/physical attack vector. Successful exploitation could result in a complete loss of confidentiality, integrity, and availability of the data stored on the encrypted volume. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Windows BitLocker

Timeline

  • 2026-06-09: advisory: Initial disclosure by Microsoft and NVD

References

Related threats