CVE-2025-48804PoC(microsoft / windows_10_1507)

CRITICALCVSS 6.8 · MEDIUM

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-349

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 6 signals
  • General: 3 classified signals
  • Peaked 4d ago at 5 mentions (2026-05-12); latest day: 1
  • 13 total mentions across 6 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_22h2windows_11_23h2windows_11_24h2windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline13 mentions / 6d
01345Mentions · 2026-05-08: 3Mentions · 2026-05-12: 5Mentions · 2026-05-14: 2Mentions · 2026-05-15: 1Mentions · 2026-05-18: 1Mentions · 2026-09-06: 1PoC Mentioned / Linked · 2026-05-08: 2PoC Mentioned / Linked · 2026-05-12: 3PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-09-06: 1Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-12: 3Exploit Tool / Code · 2026-09-06: 1Active Exploitation · 2026-05-12: 1Patch / Workaround · 2026-05-08: 2Patch / Workaround · 2026-05-12: 2Patch / Workaround · 2026-09-06: 1Technical Details · 2026-05-08: 2Technical Details · 2026-05-12: 2Technical Details · 2026-05-18: 1Technical Details · 2026-09-06: 105-0805-1205-1405-1505-1809-06
Signal classification6 categories
PoC
538.5%
General
323.1%
Exploit
215.4%
Disclosure
17.7%
Active Exploitation
17.7%
Patch
17.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-083
Disclosure1Exploit1PoC1
2026-05-125
Active Exploitation1Patch1PoC3
2026-05-142
General1PoC1
2026-05-151
General1
2026-05-181
General1
2026-09-061
Exploit1
Full discourse13 posts
  • Nicolas Krassas@Dinosn
    PoC

    Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804 https://www.intrinsec.com/en/contournement-bitlocker-la-realite-des-downgrade-attacks/

    Post summary

    The post announces a quick BitLocker bypass via a downgrade attack against CVE‑2025‑48804, citing an external link that likely contains a PoC; however, no active exploitation, patches, or detailed technical data are provided.

    021050254.9K
    158.1K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    Public PoC Alert: The BitUnlocker Downgrade Attack bypasses BitLocker on patched Windows 11 machines in under 5 minutes. Learn how to secure your TPM with a PIN. #BitLocker #Windows11 #CyberSecurity #InfoSec #BitUnlocker #PoC #GitHub #ZeroDay #TechNews https://securityonline.info/bitunlocker-windows-11-poc-downgrade-attack-cve-2025-48804/ https://t.co/QPlbimmeCd

    Post summary

    The post announces a public proof‑of‑concept for a downgrade attack that bypasses BitLocker on patched Windows 11, and recommends securing the TPM with a PIN as a workaround.

    09043233.3K
    12.5K followersView on X
  • 🕳@sekurlsa_pw
    Exploit

    Downgrade attack for Bitlocker CVE-2025-48804 “July 2025 patch fixes this in bootmgfw.efi, so any pre-patch bootmgfw.efi can be used for a downgrade attack, provided the target does not enforce a boot-manager version (SVN) (which comes with KB5025885).” https://github.com/garatc/BitUnlocker

    Post summary

    The post announces that a pre‑patch bootmgfw.efi can enable a downgrade attack on BitLocker (CVE‑2025‑48804), highlights that patching in July 2025 (KB5025885) mitigates the risk, and provides a reference to exploit code.

    0302312795
    2.7K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 #CVE-2025-48804 Exposed: How the 'BitUnlocker' Downgrade Attack Shatters #Windows 11 BitLocker Encryption in Under 5 Minutes + Video https://undercodetesting.com/cve-2025-48804-exposed-how-the-bitunlocker-downgrade-attack-shatters-windows-11-bitlocker-encryption-in-under-5-minutes-video/ Educational Purposes!

    Post summary

    The post highlights a demonstration video showcasing how CVE‑2025‑48804 can be exploited via the BitUnlocker downgrade attack to break Windows 11 BitLocker encryption in under five minutes.

    00012677
    568 followersView on X
  • Tre B@trerbbb
    Patch

    microsoft dropped CVE-2025-48804. an unauth bug, CVSS high, exploit available. if you have microsoft in your stack, block external access to the affected endpoint until patched. #Microsoft #0day #CVE-2025-48804 https://valtikstudios.com/blog

    Post summary

    Microsoft disclosed CVE-2025‑48804, an unauthenticated vulnerability with a high CVSS score and available exploit; administrators are urged to block affected endpoints until a patch is applied.

    01010695
    15 followersView on X
  • NomadSecurity@nomadsec_io
    General

    Coverage tied to CVE-2025-48804 / WinRE describes boot-chain manipulation where legacy signing trust can keep an old bootmgr story valid.

    Post summary

    The text briefly references CVE-2025-48804 and hints at boot-chain manipulation via legacy signing trust, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    100001.2K
    9 followersView on X
  • Upgrade Options Ltd@upgradeoptions
    General

    ⚠️ BitUnlocker Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes Source: https://cybersecuritynews.com/bitunlocker-downgrade-attack-on-windows-11/ @The_Cyber_News The attack is rooted in CVE-2025-48804, one of four critical zero-day vulnerabilities. #ICYMI https://t.co/QQVBzzoB7J

    Post summary

    The post announces a Windows 11 attack using CVE-2025-48804, highlighting its critical status but lacking any PoC, exploit code, patch information or technical detail.

    000001.5K
    2.5K followersView on X
  • Upgrade Options Ltd@upgradeoptions
    General

    ⚠️ BitUnlocker Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes Source: https://cybersecuritynews.com/bitunlocker-downgrade-attack-on-windows-11/ @The_Cyber_News The attack is rooted in CVE-2025-48804, one of four critical zero-day vulnerabilities.

    Post summary

    The tweet references CVE-2025-48804 as the root of a Windows 11 BitUnlocker attack, but offers no PoC, exploit details, or technical information.

    000001.3K
    2.5K followersView on X
  • Azmir Ahmed@Im_Azmir
    PoC

    Security Alert — BitLocker Downgrade Attack (CVE-2025-48804) The PoC is publicly available on GitHub. Audit your BitLocker configurations now. https://t.co/ztRzegmLz8

    Post summary

    The post announces a Proof of Concept for CVE‑2025‑48804, a BitLocker downgrade attack, which is publicly available on GitHub and urges users to audit their BitLocker configurations.

    000001.3K
    45 followersView on X
  • Alborz Safe@EthicalSafe
    PoC

    مکانیزم رمزمگاری Bitlocker زیر 5 دقیقه در ویندوز 11 دور زده شد. به تازگی هکرها توانسته اند poc مربوط به آسیب پذیری با کد شناسایی CVE-2025-48804 که مربوط به Bitlocker می باشد را با حمله ای به نام BitUnlocker Downgrade ، ارائه دهند. https://t.co/AINZGyoFnB

    Post summary

    The post announces a Proof of Concept for CVE‑2025‑48804 with an exploit named BitUnlocker Downgrade and provides a link, but does not discuss patches, active exploitation, or detailed vulnerability specifics.

    00000213
    4 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    BREAKING: New BitUnlocker downgrade attack exploits CVE-2025-48804 to bypass Windows 11 BitLocker and decrypt disks with physical access in under 5 minutes. https://threatcluster.io/cluster/new-bitunlocker-attack-compromises-windows-11-disk-encryptio-0f4d968d

    Post summary

    The post reports that the new BitUnlocker downgrade attack is actively exploiting CVE-2025-48804 to bypass BitLocker on Windows 11, enabling physical‑access decryption in under five minutes.

    00000667
    244 followersView on X
  • ALHaithem Thebat@alhaithem
    Exploit

    ⏱️ تجاوز BitLocker في أقل من 5 دقائق CVE-2025-48804 – Downgrade Attack في يوليو 2025، فريق Microsoft STORM كشف سلسلة هجوم كاملة ضد BitLocker عبر WinRE. الفكرة: الـ Boot Manager يتحقق من WIM شرعي، لكن عند إضافة WIM ثانٍ داخل SDI بجدول معدل، يتم التحقق من الأول بينما يتم الإقلاع من الثاني (المخترق). 🔎 لماذا الإصلاح غير كافٍ؟ Secure Boot يتحقق من شهادة التوقيع فقط، وليس من الإصدار. أي bootmgfw.efi قديم وموقع بـ PCA 2011 يظل صالحًا، حتى لو كان يحتوي على الثغرة. ⚡ خطوات الهجوم: • وصول فيزيائي إلى الجهاز المستهدف • تحضير BCD معدل يعيد توجيه WinRE إلى SDI مُفخخ • الإقلاع عبر USB أو PXE باستخدام bootmgfw.efi قديم موقع بـ PCA 2011 • تحميل WinRE المخترق دون كشف التلاعب • الـ TPM يفرج عن مفتاح BitLocker بشكل طبيعي • فتح الطرفية مع وحدة OS مفككة التشفير 🛡️ الحماية: • تفعيل BitLocker PIN عند الإقلاع • ترحيل Boot Manager إلى شهادة CA 2023 وإلغاء PCA 2011 عبر KB5025885 • اعتماد SVN (Secure Version Number) لتتبع الإصدارات 🎯 الهدف: جعل الهجوم أسرع وأوضح وأقل تعقيدًا، لكنه يذكّرنا أن الحماية الحقيقية تتطلب أكثر من مجرد تحديثات.

    Post summary

    The post outlines a full downgrade attack chain against BitLocker (CVE‑2025‑48804), detailing how an attacker can use an old bootloader signed with PCA 2011 to load a compromised WinRE, and it lists remediation steps including a BitLocker PIN, updated boot manager, and disabling the obsolete certificate (KB5025885).

    000001.2K
    368 followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    Disclosure

    اكتشاف طريقة لتجاوز Bitlocker في أقل من 5 دقائق باستخدام هجوم تخفيض الإصدار على CVE-2025-48804. A method has been discovered to bypass Bitlocker in under 5 minutes using a downgrade attack on CVE-2025-48804. This highlights the importance of staying updated with security patches. https://www.intrinsec.com/en/contournement-bitlocker-la-realite-des-downgrade-attacks/ #CyberSecurity #InfoSec #Vulnerability

    Post summary

    A new downgrade attack method that can bypass Bitlocker in under five minutes was disclosed for CVE-2025-48804, with a reference link and a reminder to apply patches, but no public exploit code or evidence of active exploitation.

    000001.0K
    63 followersView on X
CPE platform detail18 entries

18 of 18 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507--x64
OSmicrosoftwindows_10_1507--x86
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more