Microsoft disables BitLocker security fix, advises manual mitigation
ID: 0ef38992-cfc6-5fcb-962c-e213dc25976a
STIX ID: report--0ef38992-cfc6-5fcb-962c-e213dc25976a
Feed Name: Bleeping Computer
Microsoft disabled a fix for CVE-2024-38058 — a vulnerability that can let an attacker bypass BitLocker encryption with physical access — after the update caused firmware incompatibilities that put some devices into BitLocker recovery. Microsoft now recommends applying a four-stage mitigation from KB5025885 that requires multiple restarts and which, if applied on devices using Secure Boot, cannot be reverted even by reformatting; the company also issued a separate fix for BitLocker recovery issues but did not link that root cause to the CVE.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
