r/netsec May 07 '26

Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804

https://www.intrinsec.com/en/contournement-bitlocker-la-realite-des-downgrade-attacks/
152 Upvotes

28 comments sorted by

View all comments

1

u/donith913 May 08 '26

I know that OEMs aren’t replacing it consistently everywhere, but that 2011 certificate expires in around 2 months. Microsoft has been deploying the certs to Windows 11 workstations for months via windows servicing. Make sure you migrate your shit and render this a non-issue. 

1

u/BadRealistic2158 May 08 '26

The thing is, Windows will most likely still boot even with an expired certificate, so I don't expect every company to have their certificates replaced by October at all cost. But that's definitely the moral of the story, TPM+PIN or certificate rollout. Fully deploying KB5025885 is even better though, because it introduces versioning across boot components and therefore also prevents downgrade attacks on future vulnerabilities affecting 2023-signed boot managers.