CVE-2025-48804

MEDIUM

Windows BitLocker - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-48804. PoCs published by garatc.

AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2025-48804, demonstrating a BitLocker downgrade attack via a patched boot manager and SDI file. The exploit leverages Secure Boot trust in the PCA 2011 certificate to bypass BitLocker encryption on fully patched Windows 11 systems.

Description

Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Exploits (1)

github WORKING POC
by garatc · pythonpoc
https://github.com/garatc/BitUnlocker

This repository contains a functional proof-of-concept for CVE-2025-48804, demonstrating a BitLocker downgrade attack via a patched boot manager and SDI file. The exploit leverages Secure Boot trust in the PCA 2011 certificate to bypass BitLocker encryption on fully patched Windows 11 systems.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Windows 11 BitLocker (pre-July 2025 patch)
No auth needed
Prerequisites: Physical access to target device · Secure Boot trusts Microsoft Windows PCA 2011 · PXE boot or alternative delivery method
devstral-2 · analyzed Apr 30, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 6.8
EPSS 0.0053
EPSS Percentile 67.4%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-349
Status published
Products (15)
microsoft/windows_10_1507 < 10.0.10240.21073 (2 CPE variants)
microsoft/windows_10_1607 < 10.0.14393.8246 (2 CPE variants)
microsoft/windows_10_1809 < 10.0.17763.7558 (2 CPE variants)
microsoft/windows_10_21h2 < 10.0.19044.6093
microsoft/windows_10_22h2 < 10.0.19045.6093
microsoft/windows_11_22h2 < 10.0.22621.5624
microsoft/windows_11_23h2 < 10.0.22631.5624
microsoft/windows_11_24h2 < 10.0.26100.4652
microsoft/windows_server_2012
microsoft/windows_server_2012 r2
... and 5 more
Published Jul 08, 2025
Tracked Since Feb 18, 2026