Tech & Science

Hacker Demonstrates BitLocker Vulnerability in Windows 11

60
microsoft

A hacker has demonstrated that Windows 11’s BitLocker encryption is still vulnerable, even after a reported fix.

At the Chaos Communication Congress, hacker Thomas Lambertz showcased how users can bypass BitLocker encryption with just one-time physical device access and a network connection.

Bitpixie Attack Still Works

This vulnerability, known as CVE-2023-21563, was believed to have been fixed in November 2022. However, Lambertz’s demonstration revealed that the fix was insufficient.

By exploiting a “bitpixie” attack, hackers can use Secure Boot to start an outdated Windows bootloader, extract the encryption key into memory, and then use Linux to retrieve the key.

Why the Fix Didn’t Work

Microsoft’s attempt to fix the issue was hindered by UEFI firmware storage space limitations. New Secure Boot certificates, which could address this vulnerability, may not be available until 2026.

In the meantime, users can protect themselves by adding a PIN to their BitLocker or disabling network access in the BIOS.

Risk for Businesses and Governments

While everyday users are unlikely to face this threat, the vulnerability poses a significant risk to businesses, enterprises, and government organizations.

With just a single instance of physical access and a USB network adapter, hackers could decrypt BitLocker-protected drives, making it a serious concern for high-security environments.

For more detailed technical insights, the full presentation from the Chaos Communication Congress is available online.

Written by
Sazid Kabir

I've loved music and writing all my life. That's why I started this blog. In my spare time, I make music and run this blog for fellow music fans.

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Stay updated with nomusica.com. Add us to your preferred sources to see our latest updates first.

Related Articles

The moon moves in front of the sun in a rare "ring of fire" solar eclipse as seen from Singapore on December 26, 2019.
Tech & Science

“Ring of Fire” Solar Eclipse to Light Up Antarctica on Feb. 17

A rare “ring of fire” solar eclipse will take place on Tuesday,...

Artificial Intelligence (AI)
Tech & Science

AI.com Sold for $70 Million as Crypto.com CEO Bets Big on Artificial Intelligence

Crypto.com co-founder and CEO Kris Marszalek has entered the artificial intelligence space...

ChatGPT 5
AITech & Science

AI Experts Say Stop Relying on ChatGPT Alone

ChatGPT is one of the most popular AI tools in the world,...

Artificial Intelligence — AI
AITech & Science

AI Floods Research Papers, Scientists Call for Stricter Disclosure

Scientists are raising alarms over a surge of low-quality AI-generated research papers,...