Researchers detailed multiple attack paths that can defeat or weaken Microsoft BitLocker on systems using TPM-only unlock, showing that physical access remains enough to recover disk encryption keys or bypass pre-boot protections in common configurations. Neodyme revisited the Bitpixie technique tied to CVE-2023-21563, describing how attackers can downgrade the Windows Boot Manager, abuse a PXE soft-reboot path, and recover the Volume Master Key from memory without the user’s password. A follow-up analysis said Microsoft has struggled to fully close downgrade paths because Secure Boot revocation capacity is limited, older Microsoft-signed bootloaders remain broadly trusted, and stricter PCR bindings have caused recovery and compatibility problems in the field.
Separate research from MDSec showed that Dell UEFI firmware can be modified offline at the SPI flash level to disable pre-boot DMA protections while leaving BIOS settings appearing unchanged, enabling follow-on DMA attacks against Windows 11 devices protected by TPM-only BitLocker and, in some cases, privilege escalation even on TPM+PIN systems when the PIN is known. A public GitHub project compiling BitLocker attack techniques further underscored the breadth of the issue, cataloging hardware and software methods ranging from TPM bus sniffing and fTPM glitching to bootloader, WinRE, and recovery-environment flaws across numerous CVEs. Across the disclosures, the consistent mitigation theme was to avoid relying on TPM-only unlock where possible, apply Microsoft’s Secure Boot certificate updates such as KB5025885, and require a pre-boot PIN to materially raise the bar for physical attackers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository was published compiling public BitLocker attack techniques and vulnerabilities, especially those affecting TPM-only deployments. The list covered hardware and software attacks, downgrade scenarios, and multiple CVEs with notes on disclosures, fixes, and unfixed issues.
MDSec described a method to modify Dell UEFI firmware offline at the SPI flash level to disable pre-boot DMA protections without changing what the BIOS interface reports. The post said this could enable DMA-based attacks against Windows 11 systems using TPM-only BitLocker and support privilege escalation on TPM+PIN systems when the PIN is known.
Neodyme published a follow-up analysis arguing that Microsoft has struggled to fully fix TPM-only BitLocker downgrade attacks because of Secure Boot design tradeoffs, DBX revocation limits, and compatibility risks. The post also described Microsoft's July 2024 mitigation for CVE-2024-38058 and its August 2024 reversal due to firmware incompatibilities.
Neodyme published an analysis of the Bitpixie attack centered on CVE-2023-21563, showing that physical attackers can downgrade Windows Boot Manager and recover the BitLocker Volume Master Key from memory. The post said the issue remained practically exploitable on TPM-only BitLocker Device Encryption systems and recommended mitigations including a pre-boot PIN and KB5025885.
Pulse Security published an article describing a technique to extract BitLocker keys from a TPM by sniffing TPM communications. This represents a distinct technical disclosure about recovering BitLocker secrets from TPM-backed systems.
SCRT published an analysis of CVE-2022-41099, a BitLocker Drive Encryption bypass. This is a distinct BitLocker vulnerability disclosure and technical write-up not already captured in the existing timeline.
Researchers published the faulTPM paper describing compromise of the AMD Secure Processor underlying AMD firmware TPMs, exposing complete TPM state and enabling extraction of secrets sealed to the fTPM. The paper said this enabled the first demonstrated attack against full-disk encryption backed by an fTPM, including BitLocker’s TPM-only protector, with 2–3 hours of physical access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcemdsec.co.uk
Open sourceneodyme.io
Open sourceneodyme.io
Open sourcepulsesecurity.co.nz
Open sourceblog.scrt.ch
Open sourcearxiv.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.