SB2025011472 - Multiple vulnerabilities in Microsoft Windows BitLocker 



SB2025011472 - Multiple vulnerabilities in Microsoft Windows BitLocker

Published: January 14, 2025 Updated: March 10, 2025

Security Bulletin ID SB2025011472
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Physical access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Not Failing Securely ('Failing Open') (CVE-ID: CVE-2025-21210)

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application in Windows BitLocker. An attacker with physical access can gain unauthorized access to sensitive information on the system.


2) Information disclosure (CVE-ID: CVE-2025-21214)

The vulnerability allows a local attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application in Windows BitLocker. An attacker with physical access can gain unauthorized access to sensitive information on the system.


Remediation

Install update from vendor's website.