Bypassing BitLocker via a downgrade attack

The article examines a technique for bypassing BitLocker through a downgrade attack, in which vulnerable versions of the Windows Boot Manager are loaded. Despite installed updates, outdated boot components remain trusted within the Secure Boot chain, allowing an attacker to replace the boot environment and run the system in a compromised state without breaking the chain of trust.
The attack requires physical access and is carried out using modified boot images, enabling the extraction of encryption keys after system initialization. The core issue lies in the lack of revocation of vulnerable binaries in the UEFI dbx, making the attack reproducible.
💬 Discuss
Vendors
Intrinsec
Github
Products
Bitlocker
Bitunlocker
Secure Boot
Uefi
Windows Boot Manager