Executive brief
Windows BitLocker, the encryption system that protects data on Windows devices, contains a heap buffer overflow vulnerability. An authorized local user could exploit this flaw to run arbitrary code with elevated privileges, potentially gaining full control of the device and access to encrypted data.
Technical details
A heap-based buffer overflow exists in Windows BitLocker that can be triggered by a local, authenticated attacker. The vulnerability allows arbitrary code execution in the context of the BitLocker service, requiring local access and existing user privileges on the system. A patch has been released by Microsoft.
Affected products
- Microsoft Windows BitLocker
Timeline
- 2026-09-08: disclosed