Microsoft disclosed multiple security feature bypass vulnerabilities affecting Windows BitLocker and Windows Boot Manager, publishing advisories for CVE-2025-48804, CVE-2025-48001, CVE-2025-55338, and CVE-2022-30203. The BitLocker issues were identified as bypass flaws rather than remote code execution bugs, indicating a risk that attackers could undermine disk encryption protections or related trust controls under certain conditions.
The advisories show a recurring focus on protections tied to the Windows boot chain and full-disk encryption, with three separate BitLocker bypass CVEs and one Boot Manager bypass CVE documented by Microsoft. While Microsoft did not provide public synopses in the referenced notices, the updates signal that organizations relying on BitLocker and secure startup protections should prioritize review and deployment of the relevant Windows security patches to reduce the chance of pre-boot or local protection mechanisms being circumvented.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft released a Security Update Guide entry for CVE-2025-55338, identified as a Windows BitLocker Security Feature Bypass Vulnerability. The reference indicates disclosure in October 2025.
Microsoft published Security Update Guide advisories for two Windows BitLocker Security Feature Bypass Vulnerabilities, CVE-2025-48001 and CVE-2025-48804. Both advisories were released on the same day.
Microsoft released a Security Update Guide entry for CVE-2022-30203, described as a Windows Boot Manager Security Feature Bypass Vulnerability. This is the earliest disclosed event in the provided references.
4 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.