Bypassing BitLocker via a downgrade attack
Attack Techniques & Methods2026-05-14, 08:32
The article examines a technique for bypassing BitLocker through a downgrade attack, in which vulnerable versions of the Windows Boot Manager are loaded. Despite installed updates, outdated boot components remain trusted within the Secure Boot chain, allowing an attacker to replace the boot environment and run the system in a compromised state without breaking the chain of trust.
The attack requires physical access and is carried out using modified boot images, enabling the extraction of encryption keys after system initialization. The core issue lies in the lack of revocation of vulnerable binaries in the UEFI dbx, making the attack reproducible.
📎 Article: https://www.intrinsec.com/en/contournement-bitlocker-la-realite-des-downgrade-attacks/
⚙️ PoC: https://github.com/garatc/BitUnlocker
💬 Discuss
Vendors
Products