Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-48804. PoCs published by garatc.
AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2025-48804, demonstrating a BitLocker downgrade attack via a patched boot manager and SDI file. The exploit leverages Secure Boot trust in the PCA 2011 certificate to bypass BitLocker encryption on fully patched Windows 11 systems.
Description
Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
Exploits (1)
This repository contains a functional proof-of-concept for CVE-2025-48804, demonstrating a BitLocker downgrade attack via a patched boot manager and SDI file. The exploit leverages Secure Boot trust in the PCA 2011 certificate to bypass BitLocker encryption on fully patched Windows 11 systems.
References (1)
Scores
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H