Race Condition Vulnerability in Microsoft Windows BitLocker
CVE-2025-48818

6.8MEDIUM

What is CVE-2025-48818?

A time-of-check time-of-use (TOCTOU) race condition in Microsoft Windows BitLocker leads to a potential security feature bypass. This vulnerability allows unauthorized attackers to exploit the system during a physical attack, thereby compromising sensitive data and system integrity. The flaw specifically arises in the timing between checking the security state and using it, creating an opening for exploitation if an attacker has physical access to the system.

Affected Version(s)

Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.21073

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8246

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.7558

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48818 : Race Condition Vulnerability in Microsoft Windows BitLocker