Executive brief
A security bypass vulnerability exists in Microsoft BitLocker, the full-disk encryption feature used to protect data on Windows devices. An attacker with physical access to a powered-off or locked device could potentially bypass encryption protections to access sensitive files. This could lead to the unauthorized disclosure of corporate data or tampering with the operating system if a device is lost or stolen.
Technical details
A protection mechanism failure (CWE-693) exists in Windows BitLocker across multiple versions of Windows 10, Windows 11, and Windows Server 2016. The vulnerability allows an unauthenticated attacker with physical access to the target hardware to bypass disk encryption security features. Successful exploitation could result in high confidentiality and integrity impacts, potentially allowing the attacker to read or modify encrypted data. The attack requires physical presence but no prior administrative privileges or user interaction. Microsoft has released security updates to address this issue in the affected versions.
Affected products
- Microsoft Windows 10 Version 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Version 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 Standard and Server Core installations
Timeline
- 2026-07-14: advisory: Initial disclosure by Microsoft and NVD publication
- 2026-07-14: patched: Security updates released by Microsoft