Security features bypass in Windows Server and Windows - CVE-2025-55338

 

Security features bypass in Windows Server and Windows - CVE-2025-55338

Published: October 14, 2025


Vulnerability identifier: #VU117104
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-55338
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Microsoft
Affected software:
Windows Server
Windows

Detailed vulnerability description

The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to missing ability to patch ROM code in Windows BitLocker. An attacker with physical access can bypass a security feature and gain access to encrypted data.


How to mitigate CVE-2025-55338

Install updates from vendor's website.

Sources