Microsoft Disables Fix for BitLocker Vulnerability Due to Firmware Issues

15 Aug 2024

Microsoft has taken a significant step in addressing a critical security vulnerability, CVE-2024-38058, which pertains to a bypass of the BitLocker Device Encryption feature. This flaw poses a risk by allowing potential attackers with physical access to a device to circumvent encryption and access sensitive data. However, the company has recently announced the disabling of a fix intended to mitigate this issue due to complications arising from firmware incompatibility.

Details of the Vulnerability and Response

In a communication released on Wednesday, Microsoft acknowledged the challenges faced by users who applied the initial fix. The company noted, “When customers applied the fix for this vulnerability to their devices, we received feedback about firmware incompatibility issues that were causing BitLocker to go into recovery mode on some devices.” As a result, the fix will be disabled with the rollout of the August 2024 security updates.

For those seeking to safeguard their systems against the CVE-2024-38058 vulnerability, Microsoft recommends following the mitigation measures outlined in the KB5025885 advisory. However, this approach is not without its complexities. Users will now need to engage in a four-stage procedure that necessitates restarting the affected device a total of eight times.

Moreover, Microsoft has issued a caution regarding the application of these mitigations on devices utilizing Secure Boot. Once the mitigation is enabled, it cannot be undone, even if the device is reformatted. The company warns, “After the mitigation for this issue is enabled on a device… it cannot be reverted if you continue to use Secure Boot on that device.” This highlights the importance of understanding the implications and thoroughly testing the process before proceeding.

Recent Updates and Ongoing Issues

In conjunction with this development, Microsoft addressed a known issue that emerged following the July Windows security updates, which inadvertently caused some devices to boot into BitLocker recovery mode. While this situation aligns with the firmware incompatibility that led to the disabling of the CVE-2024-38058 fix, Microsoft has refrained from providing specific details regarding the root cause or the resolution of this issue.

The company has simply advised affected users to install the latest updates for their devices, emphasizing that these updates contain essential improvements and resolutions for various issues, including the recent booting problems. However, no direct connection has been made between this bug and the CVE-2024-38058 vulnerability.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6679343
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1401730
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
557546
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
461285
downloads

News and reviews for Desktop Windows

Tempest Rising: New Superweapons Revitalize Gameplay

Slipgate Ironworks adds powerful superweapons to Tempest Rising, enhancing strategic depth.

Read more

Team Cherry Skips Game Awards Despite Silksong Nomination

Team Cherry may skip The Game Awards, opting out of a potential Silksong win for Game of the Year due to their busy schedule.

Read more

Norton Offers 75% Off on Black Friday Antivirus Deals

Norton slashes prices on antivirus software during Black Friday. Save on Norton 360 Deluxe, available until 2025-11-28.

Read more

Hytale Early Access Launches on 2026-01-13

Hypixel Studios schedules Hytale early access for 2026-01-13, with pricing reflecting its 'alpha' state.

Read more

Score PC Games Deals This Black Friday

Black Friday 2025 brings PC games deals across Steam, Epic Games Store, and GOG, with more sales following during the holiday season.

Read more

Microsoft Sets 2034 Deadline for WINS Migration from Windows

Microsoft plans to phase out WINS by 2034, urging Windows users to migrate to DNS.

Read more

Helldivers 2 Offers 31% Black Friday Discount for 24 Hours

Helldivers 2 gets a significant 31% discount for Black Friday, available for one day, providing a cost-effective gaming experience.

Read more

Valve Defends AI Disclosures on Steam Amid Criticism

Valve advocates for AI disclosures in gaming, arguing they inform consumers. Critics question their necessity.

Read more

Clair Obscur Discount: Save 45% on PC Purchase

Clair Obscur: Expedition 33, a turn-based RPG by Sandfall Interactive, is 45% off on PC. Offer available during Black Friday 2025.

Read more

New Mod Manager for Total War: Warhammer 3 Launched

Creative Assembly introduces Total War: Warhammer 3 mod manager in early access on Steam, aiming for improved mod management.

Read more