BitLocker encryption feature was introduced by Microsoft in Windows Vista to ensure data security. It turned out that the long-standing BitLocker vulnerability, which allowed hackers to bypass the security mechanism, is still relevant, despite the fact that Microsoft has released a patch that fixes it.

Image Source: Hack Capital / unsplash.com

This became known at the recent Chaos Communication Congress, when hacker Thomas Lambertz showed how to exploit an old, supposedly fixed vulnerability in Microsoft encryption technology. Interestingly, he was able to do this on a device with a fresh version of Windows 11, which had the latest security updates installed.

We are talking about the vulnerability CVE-2023-21563, which was named “bitpixie” and which became known in 2022. It seems that Microsoft has never been able to completely solve this problem. Exploiting the mentioned vulnerability allows you to bypass the encryption function and gain full access to the data, although this will require physical access to the attacked device.

To exploit the mentioned vulnerability, Lambertz used Secure Boot technology, thanks to which he was able to launch an old version of the Windows boot loader. This approach allowed us to extract the encryption key into memory and use Linux to extract the data from memory. For ordinary users, this problem is not very relevant. However, in the corporate segment, BitLocker is used much more often, and in current builds of Windows 11, the encryption function is enabled by default. This means that similar attacks could be used by hackers to extract and decrypt data from corporate Windows 11 devices.

admin

Share
Published by
admin

Recent Posts

The two largest photo stocks in the world are planning a merger, but antitrust regulators may prevent it

Getty Images and Shutterstock are in merger talks amid growing demand for visual content and…

5 hours ago

The most anticipated games of 2025

Assassin’s Creed Shadows In Assassin's Creed Shadows, Ubisoft returns to the idea of ​​two playable…

6 hours ago

South Korean battery makers have begun tightening their belts to weather a tough year.

Declining electric vehicle sales in 2024 and expectations of further deterioration as Donald Trump returns…

10 hours ago

Acer will soon introduce Nitro Blaze 11 and Blaze 8 portable consoles with large screens

Acer intends to announce portable gaming consoles Nitro Blaze 11 and Blaze 8 next week…

12 hours ago

PowerColor showed the appearance of the upcoming Radeon RX 9070 XT Red Devil video card

In anticipation of the large-scale announcement of new generation video cards from AMD and Nvidia,…

14 hours ago

BenQ showed the fastest monitor in the world – 600 Hz Zowie XL2586X+ for e-sportsmen

BenQ's Zowie gaming brand has unveiled the XL2586X+ 24.1-inch gaming monitor designed for eSports. The…

14 hours ago