Proof-of-Concept Disclosed: New “BitUnlocker” Attack Bypasses Patched Windows 11 BitLocker via Certificate Downgrade
ID: 702a6375-84a2-56dd-aff6-d3695fef0ffe
STIX ID: report--702a6375-84a2-56dd-aff6-d3695fef0ffe
Feed Name: securityonline.info
Threat Score
A proof-of-concept ‘BitUnlocker Downgrade Attack’ leverages signed but outdated bootmgfw.efi binaries to bypass BitLocker on fully patched Windows 11 systems (CVE-2025-48804). By replacing the patched boot manager and loading a manipulated WinRE image, an attacker with physical access can trigger the TPM to release BitLocker keys and obtain a decrypted OS volume in minutes; mitigations include enabling TPM+PIN and migrating to the Windows UEFI CA 2023 certificate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
