logo

Microsoft disables BitLocker security fix, advises manual mitigation

ID: 0ef38992-cfc6-5fcb-962c-e213dc25976a

STIX ID: report--0ef38992-cfc6-5fcb-962c-e213dc25976a

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-08-15

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft disabled a fix for CVE-2024-38058 — a vulnerability that can let an attacker bypass BitLocker encryption with physical access — after the update caused firmware incompatibilities that put some devices into BitLocker recovery. Microsoft now recommends applying a four-stage mitigation from KB5025885 that requires multiple restarts and which, if applied on devices using Secure Boot, cannot be reverted even by reformatting; the company also issued a separate fix for BitLocker recovery issues but did not link that root cause to the CVE.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.