Microsoft Disables Fix for BitLocker Vulnerability Due to Firmware Issues

15 Aug 2024

Microsoft has taken a significant step in addressing a critical security vulnerability, CVE-2024-38058, which pertains to a bypass of the BitLocker Device Encryption feature. This flaw poses a risk by allowing potential attackers with physical access to a device to circumvent encryption and access sensitive data. However, the company has recently announced the disabling of a fix intended to mitigate this issue due to complications arising from firmware incompatibility.

Details of the Vulnerability and Response

In a communication released on Wednesday, Microsoft acknowledged the challenges faced by users who applied the initial fix. The company noted, “When customers applied the fix for this vulnerability to their devices, we received feedback about firmware incompatibility issues that were causing BitLocker to go into recovery mode on some devices.” As a result, the fix will be disabled with the rollout of the August 2024 security updates.

For those seeking to safeguard their systems against the CVE-2024-38058 vulnerability, Microsoft recommends following the mitigation measures outlined in the KB5025885 advisory. However, this approach is not without its complexities. Users will now need to engage in a four-stage procedure that necessitates restarting the affected device a total of eight times.

Moreover, Microsoft has issued a caution regarding the application of these mitigations on devices utilizing Secure Boot. Once the mitigation is enabled, it cannot be undone, even if the device is reformatted. The company warns, “After the mitigation for this issue is enabled on a device… it cannot be reverted if you continue to use Secure Boot on that device.” This highlights the importance of understanding the implications and thoroughly testing the process before proceeding.

Recent Updates and Ongoing Issues

In conjunction with this development, Microsoft addressed a known issue that emerged following the July Windows security updates, which inadvertently caused some devices to boot into BitLocker recovery mode. While this situation aligns with the firmware incompatibility that led to the disabling of the CVE-2024-38058 fix, Microsoft has refrained from providing specific details regarding the root cause or the resolution of this issue.

The company has simply advised affected users to install the latest updates for their devices, emphasizing that these updates contain essential improvements and resolutions for various issues, including the recent booting problems. However, no direct connection has been made between this bug and the CVE-2024-38058 vulnerability.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
4936008
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
824339
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
417915
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
303594
downloads

News and reviews for Desktop Windows

Microsoft's Potential Handheld Gaming Plans Spark Interest

Speculation grows over a Microsoft device as a potential handheld competitor to the Steam Deck, potentially unveiled at the Xbox Games Showcase.

Read more

Hellslave RPG Available Free on Steam For Limited Time

The dark fantasy RPG Hellslave is now free on Steam, as its sequel approaches. Experience this dungeon-crawler and retain it in your library forever. Claim it by June 16.

Read more

Foxtail Unveils Hidden Gem from Comiket 81 in Gaming History

A mysterious disc titled Action RPG (Temp) C81 Demo Version reveals a rarely seen game from Comiket 81 in 2011, featuring unique stamina-based combat. The demo offers a glimpse into a creative era of RPGs, thanks to the dedicated work of developer Foxtail.

Read more

IO Interactive Unveils New James Bond Game: First Light

IO Interactive announces 007 First Light, a new video game featuring an original James Bond origin story. Players will earn their 00 status in this immersive gaming experience crafted for a fresh perspective within the Bond series.

Read more

Anvil Empires Aims to Revolutionize Medieval RTS Gaming

Anvil Empires, a medieval RTS game inspired by Age of Empires 2, offers a large-scale playtest. It combines classic strategy mechanics with MMO elements, allowing up to 1,000 players per server. The focus is on logistics and teamwork.

Read more

Atomic Heart Game Offers Up to 71% Off Sale This Year

Atomic Heart, a distinctive shooter set in a robot-dystopia, is on sale with a 71% discount. Experience the narrative of rebellion against an authoritarian regime as P-3. With elemental powers and melee combat, it promises a unique adventure at $21.09 / £15.49.

Read more

IO Interactive Reveals James Bond Game 007 First Light

IO Interactive announces 007 First Light, a new James Bond game. The long-awaited origin story adds to the Bond franchise's gaming legacy. Fans eagerly await the full reveal, marking IO Interactive's first major step since 2020.

Read more

Nightreign Patch Improves Gameplay for Singleplayer Mode

The Nightreign patch adds auto-resurrect and boosts levelling, addressing challenges in singleplayer mode. Players now experience improved balance and performance, aligning with FromSoftware's commitment to refining gameplay.

Read more

Elden Ring Patch Enhances Solo Gameplay Dynamics

Elden Ring receives a solo gameplay boost with the Nightreign patch. The update introduces automatic revival and improved rewards, enhancing gamers' experiences.

Read more

Medal of Honor Game Reimagined with Unreal Engine 5

The classic Medal of Honor Allied Assault is reimagined using Unreal Engine 5, receiving praise from original game designer Nathan Silvers. The remake highlights the enduring legacy of the game, despite the uncertain future of the Medal series.

Read more