CVE-2025-26637

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 693

Summary

CVE-2025-26637 is a vulnerability affecting Windows BitLocker, a full disk encryption feature. An attacker can exploit this issue through a physical attack, bypassing the security feature and gaining unauthorized access to encrypted data. This vulnerability poses a significant risk to organizations and individuals using BitLocker to secure their data, emphasizing the importance of safeguarding physical access to devices. Microsoft has not yet released a patch for this vulnerability, leaving affected systems vulnerable until an update is available. Users are strongly advised to take additional measures to secure their devices and data in the interim.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft