CVE-2022-41099 is a BitLocker security feature bypass in the Windows Recovery Environment (WinRE) reset workflow. In vulnerable WinRE builds, the recovery UI logic in bootmenuux.dll did not reliably relock BitLocker-protected volumes for certain recovery operations, including reset scenarios such as BasicReset and FactoryReset. During a reset operation, BitLocker decryption could begin and then be interrupted, leaving the operating system volume accessible while recovery actions continued. An attacker with physical access could abuse this state to obtain a command shell during the resumed installation or recovery process and then disable BitLocker protectors or recover BitLocker key material. Microsoft’s fix changed WinRE behavior so that reset operations require the BitLocker recovery key before proceeding, preventing unauthorized use of the recovery workflow to access a TPM-unlocked volume.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A WinRE BitLocker bypass caused by partition layout handling that allowed physical attackers to bypass BitLocker on TPM-only systems.
A BitLocker drive encryption bypass vulnerability in the Windows recovery environment that allowed an attacker to interrupt a reset process and bypass encryption safeguards.
A BitLocker bypass vulnerability in the Windows Recovery Environment (WinRE) that can allow an attacker with physical access to gain access to encrypted data on TPM-protected systems, particularly those using transparent TPM mode, by abusing recovery/reset workflows before the WinRE patch is applied.
Security feature bypass vulnerability in BitLocker.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.