CVE-2023-21563
published 2023-01-10CVE-2023-21563: BitLocker Security Feature Bypass Vulnerability BitLocker Security Feature Bypass Vulnerability
medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
1.55%
72.3th percentile
BitLocker Security Feature Bypass Vulnerability
BitLocker Security Feature Bypass Vulnerability
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19685 | 10.0.10240.19685 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5648 | 10.0.14393.5648 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3887 | 10.0.17763.3887 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3887 | 10.0.17763.3887 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2486 | 10.0.19042.2486 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2486 | 10.0.19044.2486 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2486 | 10.0.19045.2486 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1455 | 10.0.22000.1455 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.1105 | 10.0.22621.1105 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.26321 | 6.1.7601.26321 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.26321 | 6.1.7601.26321 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20778 | 6.3.9600.20778 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26321 | 6.1.7601.26321 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.21872 | 6.0.6003.21872 |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.24075 | 6.2.9200.24075 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20778 | 6.3.9600.20778 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5648 | 10.0.14393.5648 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.3887 | 10.0.17763.3887 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.1487 | 10.0.20348.1487 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_10_version_22h2 | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvelistv56.8MEDIUM
vendor_msrc6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CVEList
BitLocker Security Feature Bypass Vulnerability
cvelistv5·2023-01-10·CVSS 6.8
CVE-2023-21563 [MEDIUM] BitLocker Security Feature Bypass Vulnerability
BitLocker Security Feature Bypass Vulnerability
BitLocker Security Feature Bypass Vulnerability
Microsoft
BitLocker Security Feature Bypass Vulnerability
vendor_msrc·2023-01-10·CVSS 6.8
CVE-2023-21563 [MEDIUM] BitLocker Security Feature Bypass Vulnerability
BitLocker Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
A successful attacker could bypass the BitLocker Device Encryption feature on the system storage device. An attacker with physical access to the target could exploit this vulnerability to gain access to encrypted data.
Windows BitLocker: Windows BitLocker
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022286
Reference: https://support.microsoft.com/help/5022286
Reference: htt
No detection rules found.
No public exploits indexed.
Krebs
Microsoft Patch Tuesday, January 2023 Edition
blogs_krebs·2023-01-10·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, January 2023 Edition
Microsoft today released updates to fix nearly 100 security flaws in its Windows operating systems and other software. Highlights from the first Patch Tuesday of 2023 include a zero-day vulnerability in Windows, printer software flaws reported by the U.S. National Security Agency, and a critical Microsoft SharePoint Server bug that allows a remote, unauthenticated attacker to make an anonymous connection.
At least 11 of the patches released today are rated “Critical” by Microsoft, meaning they could be exploited by malware or malcontents to seize remote control over vulnerable Windows systems with little or no help from users.
Of particular concern for organizations running Microsoft SharePoint Server is CVE-2023-21743. This is a Critical security bypass flaw that could allow a remote, u
Krebs
Microsoft Patch Tuesday, January 2023 Edition
blogs_krebs·2023-01-10·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, January 2023 Edition
Microsoft today released updates to fix nearly 100 security flaws in its Windows operating systems and other software. Highlights from the first Patch Tuesday of 2023 include a zero-day vulnerability in Windows, printer software flaws reported by the U.S. National Security Agency , and a critical Microsoft SharePoint Server bug that allows a remote, unauthenticated attacker to make an anonymous connection.
At least 11 of the patches released today are rated “Critical” by Microsoft, meaning they could be exploited by malware or malcontents to seize remote control over vulnerable Windows systems with little or no help from users.
Of particular concern for organizations running Microsoft SharePoint Server is CVE-2023-21743 . This is a Critical security bypass flaw that could allow a remote,
2023-01-10
Published