Microsoft Windows Server 2022
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*
A vulnerability in Windows BitLocker has been identified, allowing an unauthorized attacker to bypass the Device Encryption feature on the system storage device. This issue arises from improper enforcement of behavioral workflow, which can be exploited through a physical attack. As a result, an attacker with physical access to the device could gain access to encrypted data.
Exploitation of this vulnerability allows for unauthorized bypassing of BitLocker's Device Encryption feature, potentially leading to unauthorized access to encrypted data on the system storage device.
Users can apply the security update for this vulnerability, which is available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5066791, KB5066793, KB5066782, KB5066835, and KB5066586.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.