Microsoft disclosed that researchers found multiple Windows Recovery Environment (WinRE) weaknesses that could let an attacker with physical access bypass BitLocker protections and recover data from encrypted devices. The issues affected how WinRE handled unprotected files on recovery and EFI volumes during BitLocker auto-unlock, and included a Trusted WIM Boot bypass via Boot.sdi manipulation, abuse of ReAgent.xml scheduled operations through tttracer.exe and SetupPlatform.exe, and a Boot Configuration Data (BCD) parsing flaw that enabled a full Push Button Reset exploit chain to decrypt the OS volume. Microsoft said the four vulnerabilities were patched in the July 2025 Patch Tuesday release.
The disclosure prompted renewed guidance from the UK NCSC, which said BitLocker deployments without a pre-boot PIN remain exposed to known and future bypass techniques, including the YellowKey method that also abused WinRE. NCSC said the recurring problem is partly architectural because BitLocker does not encrypt WinRE-related files, leaving a persistent recovery-environment attack surface, and recommended enabling TPM+PIN to block these attacks by requiring user authentication before WinRE can be used. Where PINs are impractical, it advised alternatives including BitLocker Network Unlock, startup keys with TPM, and conditional access controls, while Microsoft also pointed customers to the REVISE mitigation to reduce downgrade risk.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The UK NCSC published guidance recommending that organizations configure BitLocker with a pre-boot PIN, arguing that BitLocker without a PIN remains vulnerable to YellowKey and similar WinRE-based bypasses. The guidance also suggested alternatives such as Network Unlock, Startup Keys with TPM, and conditional access controls where PIN use is impractical.
Microsoft published the 'BitUnlocker: Leveraging Windows Recovery to Extract BitLocker Secrets' blog detailing the WinRE attack surface, the four patched vulnerabilities, and mitigations such as TPM+PIN and REVISE. The post explained how the flaws could let attackers with physical access bypass BitLocker auto-unlock protections.
Microsoft fixed four vulnerabilities affecting WinRE and BitLocker in the July 2025 Patch Tuesday release: CVE-2025-48804, CVE-2025-48800, CVE-2025-48003, and CVE-2025-48818. The issues covered Boot.sdi manipulation, two ReAgent.xml scheduled-operation abuses, and a BCD/Push Button Reset exploit chain.
Microsoft Security researchers first presented their 2025 research into Windows Recovery Environment attack surfaces affecting BitLocker at Black Hat USA 2025 and DEF CON 33. The research described multiple ways physical attackers could abuse WinRE behavior to bypass BitLocker protections.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcencsc.gov.uk
Open sourcetechcommunity.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.