Microsoft Windows Server 2025
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*
A vulnerability in Windows BitLocker has been identified, allowing an unauthorized attacker to bypass the Device Encryption feature on the system storage device. This issue arises from improper enforcement of behavioral workflow, which could be exploited through a physical attack. As a result, an attacker with physical access to the device could gain access to encrypted data.
Exploitation of this vulnerability could lead to unauthorized access to encrypted data by bypassing the BitLocker Device Encryption feature on the system storage device.
Users can apply the security update KB5066835 to address this vulnerability. This security update is available through the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.