BitUnlocker bypasses TPM-only Windows 11 BitLocker

Intrinsec disclosed BitUnlocker, a downgrade attack that can bypass TPM-only Windows 11 BitLocker protections with physical access to a machine. The technique abuses a flaw in Windows recovery and deployment components and relies on older trusted boot code.

Security researchers at Intrinsec released BitUnlocker, a tool bypassing Windows 11 BitLocker encryption in under five minutes. The attack uses a downgrade technique to access drives by exploiting a gap between software patching and certificate revocation. The issue is rooted in CVE-2025-48804, a vulnerability patched in July 2025, and the flaw resides within the Windows Recovery Environment and System Deployment Image mechanism.

The attack requires physical access to the target machine. With that access, an attacker can use a flash drive to present the boot manager with a legitimate Windows Imaging Format file for integrity checks while appending a malicious payload. The system verifies the clean file but then boots the attacker’s code, which grants access to the decrypted volume.

The downgrade path is central to the technique. Because Microsoft’s legacy Windows PCA 2011 certificate remains globally trusted by Secure Boot, attackers can load an older, vulnerable boot manager and have it authenticated by the system. That allows patched systems to remain exposed when older trusted components can still be used during the boot process.

58

Impact Score

Nvidia and Abridge build clinical Artificial Intelligence model

Nvidia is partnering with Abridge on a healthcare-focused Artificial Intelligence model designed for real doctor-patient conversations. The system will run inside Abridge’s clinical scribe platform, which is already used by major health systems.

Artificial Intelligence shifts into execution and scrutiny

London Tech Week focused on responsible Artificial Intelligence deployment as companies, regulators and investors moved from ambition to implementation. OpenAI’s IPO plans, Meta’s WhatsApp dispute, drone defence partnerships and changing junior roles defined the week’s technology agenda.

Contact Us

Got questions? Use the form to contact us.

Contact Form

Clicking next sends a verification code to your email. After verifying, you can enter your message.