CVE-2024-38058 is a BitLocker security feature bypass affecting Windows systems that rely on TPM-only BitLocker or Device Encryption unlock in the default Secure Boot-based measurement profile. The issue is associated with a bootloader downgrade scenario in which BitLocker protection is not sufficiently bound to the exact bootloader image hash under the PCR 7 and PCR 11 validation profile. In this configuration, the TPM can still unseal BitLocker key material for an older Microsoft-signed bootloader, allowing an attacker to boot a downgraded but still trusted component and bypass intended boot-chain integrity protections. Microsoft briefly mitigated this class of issue by adding PCR 4 to default BitLocker protection, which binds the bootloader hash and blocks downgrade-based TPM unsealing, but that change was later rolled back because of compatibility problems on some platforms.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A BitLocker security feature bypass vulnerability tied to bootloader downgrade risk; Microsoft briefly mitigated it by re-including PCR4 in default Device Encryption TPM protector configuration.
A separate Microsoft vulnerability mentioned as having similar impact to the discussed BitLocker/bootloader issue and referenced in the context of attempted mitigations and rollback.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.