CVE-2025-55330

Published Oct 14, 2025

Last updated 20 hours ago

CVSS medium 6.1
Windows BitLocker

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-55330 is a security feature bypass vulnerability in Windows BitLocker. It stems from an improper enforcement of behavioral workflow, which can allow an attacker with physical access to bypass BitLocker protections. Specifically, the vulnerability can be exploited if an attacker gains brief physical access to a target device and induces BitLocker to accept untrusted or malformed input during boot or recovery decision logic, thus bypassing a security check. Applying the relevant vendor update is the recommended remediation.

Description
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_11_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_server_2022_23h2, windows_server_2025

Risk scores

CVSS 3.1

Type
Primary
Base score
4.6
Impact score
3.6
Exploitability score
0.9
Vector string
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

secure@microsoft.com
CWE-841

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.