CVE-2025-55682

Published Oct 14, 2025

Last updated 4 days ago

CVSS medium 6.1
Windows BitLocker

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-55682 is a security feature bypass vulnerability in Windows BitLocker. The vulnerability can be exploited through a physical attack. The vulnerability stems from improper enforcement of behavioral workflow in Windows BitLocker. An attacker with physical access could bypass security features.

Description
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_11_24h2, windows_11_25h2, windows_server_2025

Risk scores

CVSS 3.1

Type
Primary
Base score
4.6
Impact score
3.6
Exploitability score
0.9
Vector string
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

secure@microsoft.com
CWE-841

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.