Microsoft disables BitLocker security fix, advises manual mitigation

Teilen:

Microsoft has disabled a fix for a BitLocker security feature bypass vulnerability due to firmware incompatibility issues that were causing patched Windows devices to go into BitLocker recovery mode.

Tracked as CVE-2024-38058, this important severity security flaw can let attackers bypass the BitLocker Device Encryption feature and access encrypted data with physical access to the targeted device.

“When customers applied the fix for this vulnerability to their devices, we received feedback about firmware incompatibility issues that were causing BitLocker to go into recovery mode on some devices,” the company explained in a Wednesday update. “As a result, with the release of the August 2024 security updates we are disabling this fix.”

After disabling the fix, Microsoft advises those who want to protect their systems and data against CVE-2024-38058 attacks to apply mitigation measures detailed in the KB5025885 advisory.

However, instead of deploying a security update, they’ll now have to go through a 4-stage procedure that also requires restarting the impacted device eight times. Furthermore, Microsoft warns that after applying the mitigation on devices with Secure Boot, they will no longer be able to remove it, even after reformatting the disk.

“After the mitigation for this issue is enabled on a device, meaning the mitigations have been applied, it cannot be reverted if you continue to use Secure Boot on that device. Even reformatting of the disk will not remove the revocations if they have already been applied,” the company cautions.

“Please be aware of all the possible implications and test thoroughly before you apply the revocations that are outlined in this article to your device.”

During this month’s Patch Tuesday, Redmond also fixed a known issue triggered by July’s Windows security updates, which caused some Windows devices to boot into BitLocker recovery.

While this matches the firmware incompatibility issues that forced Microsoft to disable the CVE-2024-38058 fix, the company didn’t provide any information on the actual root cause or how it addressed it.

Microsoft only advised affected customers to install the latest update for their devices “as it contains important improvements and issue resolutions, including this one,” without linking the bug or its fix to the CVE-2024-38058 vulnerability in any way.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:28 pm, Jan. 22, 2025
Wetter-Symbol 3°C
L: 1° | H: 4°
overcast clouds
Luftfeuchtigkeit: 89 %
Druck: 1003 mb
Wind: 8 mph W
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:52 am
Sonnenuntergang: 4:31 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 9:00 pm
Wetter-Symbol
1° | 4°°C 1 mm 100% 18 mph 90 % 1005 mb 0 mm/h
Fr. Jan. 24 9:00 pm
Wetter-Symbol
5° | 11°°C 1 mm 100% 25 mph 89 % 1004 mb 0 mm/h
Sa. Jan. 25 9:00 pm
Wetter-Symbol
2° | 5°°C 1 mm 100% 6 mph 96 % 1013 mb 0 mm/h
So. Jan. 26 9:00 pm
Wetter-Symbol
1° | 7°°C 0 mm 0% 16 mph 95 % 1013 mb 0 mm/h
Mo. Jan. 27 9:00 pm
Wetter-Symbol
4° | 9°°C 1 mm 100% 26 mph 92 % 996 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
3° | 4°°C 0 mm 0% 4 mph 89 % 1004 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 5 mph 90 % 1004 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 7 mph 87 % 1005 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 9 mph 83 % 1004 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 16 mph 76 % 1000 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
8° | 8°°C 1 mm 100% 18 mph 71 % 999 mb 0 mm/h
Tomorrow 6:00 pm
Wetter-Symbol
6° | 6°°C 0.8 mm 80% 16 mph 72 % 1002 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 11 mph 75 % 1004 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€99,719.26
-1.86%
Ethereum(ETH)
€3,110.00
-2.45%
XRP(XRP)
€3.05
0.29%
Fesseln(USDT)
€0.96
-0.02%
Solana(SOL)
€246.90
3.25%
Dogecoin(DOGE)
€0.345933
-2.83%
USDC(USDC)
€0.96
-0.01%
Shiba Inu(SHIB)
€0.000019
-3.25%
Pepe(PEPE)
€0.000014
-5.05%
Peanut das Eichhörnchen(PNUT)
€0.341110
-4.03%
Nach oben scrollen