Converseer
No Result
View All Result
  • Home
  • Politics
  • Jobs
  • Metro
  • Sports
  • Tech
  • Health
  • News
    • Business
    • Education
    • Entertainment
    • Lifestyle
    • Science & Nature
    • Tourism
  • Trends
PRICING
SUBSCRIBE
  • Home
  • Politics
  • Jobs
  • Metro
  • Sports
  • Tech
  • Health
  • News
    • Business
    • Education
    • Entertainment
    • Lifestyle
    • Science & Nature
    • Tourism
  • Trends
No Result
View All Result
Converseer
No Result
View All Result
  • Home
  • Politics
  • Jobs
  • Metro
  • Sports
  • Tech
  • Health
  • News
  • Trends

Home » Tech » Vulnerability in Microsoft’s BitLocker Allows Hackers to Bypass Encryption

Vulnerability in Microsoft’s BitLocker Allows Hackers to Bypass Encryption

January 2, 2025
in Tech
Reading Time: 2 mins read

New York, U.S. – A critical vulnerability in Microsoft’s BitLocker encryption, identified as CVE-2023-21563, has been demonstrated to allow hackers to bypass its security with minimal effort and brief physical access to a device.

Security researcher Thomas Lambertz, known as “th0mas,” revealed this flaw during a keynote at the Chaos Communication Conference titled “Windows BitLocker: Screwed without a Screwdriver.” He showcased how attackers could exploit the vulnerability without turning on the device.

The attack requires physical access to the system. By forcing the target device into recovery mode and connecting it to a network, hackers can effectively decrypt a Windows 11 system protected by BitLocker encryption.

This discovery highlights significant risks for systems relying on BitLocker to protect sensitive data, particularly in environments where physical access to devices is not strictly controlled. Microsoft has not yet announced a specific fix for this vulnerability.

Security experts urge users and organisations to enhance physical security measures for devices and monitor Microsoft’s updates for potential patches to address this critical issue.

format,f webp Vulnerability in Microsoft's BitLocker Allows Hackers to Bypass Encryption

RELATED NEWS

How To Get 25GB Data For Free On MTN

Cross River to Train Youths in Electric Vehicle Maintenance, Manufacturing

Microsoft Engineers Confirm Native Apps Will Return to Windows 11 App Ecosystem, Breaking “Web-Centric” Dilemma

Orange Pie launches Zero 3W mini single-board computer: 16GB RAM, Wi-Fi 6, Allwinner A733 chip

Microsoft fixed the CVE-2023-21563 vulnerability in 2022, but this demonstration shows that it has not been completely fixed. BitLocker enables the “Device Encryption” feature by default in newer Windows 11 systems. The hard disk is encrypted at rest, but it is automatically decrypted when the legitimate Windows system is started.

Lambertz used an attack method called “bitpixie” to run an old version of the Windows boot loader through Secure Boot, extract the encryption key into memory, and then use the Linux system to read the memory contents and finally obtain the BitLocker key.

format,f webp Vulnerability in Microsoft's BitLocker Allows Hackers to Bypass Encryption

Microsoft has long been aware of the problem, and the permanent solution is to revoke the certificate of the vulnerable boot loader, but the memory space used to store certificates in UEFI firmware is limited, so it is difficult to fully defend against it in the short term. Microsoft plans to distribute new secure boot certificates starting in 2026, which will force motherboard manufacturers to update UEFI.

Previously, users could only protect themselves by setting a personal PIN to back up BitLocker or disabling network access in the BIOS.

Lambertz warned that even a simple USB network adapter is enough to perform this attack. For ordinary users, the risk of this attack is relatively low. But for enterprises, governments and other institutions that attach great importance to network security, only physical access and a USB network adapter are needed to decrypt BitLocker, which is undoubtedly a major security risk.

Tags: Microsoft
Next Post

Samsung Semiconductor Faces Setback as Key Chip Expert Departs

Nintendo Switch 2 Rumours: Speculation on Performance Sparks Debate

Topics

  • Latest News
  • Nigeria
  • Africa
  • Europe
  • Asia
  • Americas
  • United States

Social Media

  • WhatsApp
  • Facebook
  • X (Twitter)
  • YouTube
  • LinkedIn

Special Topics

  • Column
  • Bassey Otu
  • Bola Tinubu
  • Special Reports
  • Profile & Biography
  • Opinion
  • Latest News
  • About
  • Advertise
  • Contact
  • Daily Newsletter
  • Privacy Policy
  • Terms Of Use
  • Write For Us

© 2026 Converseer.

No Result
View All Result
  • About
  • Advertise
  • Contact
  • Daily Newsletter
  • Privacy Policy
  • Terms Of Use
  • Write For Us

© 2026 Converseer.