Executive brief
Windows BitLocker, the disk encryption feature built into Windows, contains an out-of-bounds read vulnerability that allows an authorized attacker to escalate privileges over a network. An attacker who exploits this flaw could gain administrative control over an affected system, potentially compromising encrypted data and system integrity.
Technical details
An out-of-bounds read vulnerability in Windows BitLocker allows an authenticated attacker to read memory beyond intended boundaries over the network, leading to privilege escalation. The vulnerability requires an attacker to already have some level of authorization on the system. Exploitation enables arbitrary code execution with elevated privileges.
Affected products
- Microsoft Windows BitLocker
Timeline
- 2026-09-08: disclosed