New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes
ID: f413e708-601b-54ea-a645-153e1fd5d49d
STIX ID: report--f413e708-601b-54ea-a645-153e1fd5d49d
Feed Name: cybersecurityNews.com
**Executive Summary:** BitUnlocker is a practical downgrade attack that combines CVE-2025-48804 and the continued trust of the legacy PCA 2011 signing certificate to load a pre-patch boot manager and a tampered WinRE image, allowing an attacker with physical access to decrypt BitLocker-protected volumes on many Windows 11 systems in under five minutes; a public PoC exists and mitigations include enabling TPM+PIN, deploying KB5025885 (CA 2023 migration), verifying bootmgfw.efi signatures, and removing WinRE where appropriate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
