Microsoft Disables Fix for BitLocker Vulnerability Due to Firmware Issues

15 Aug 2024

Microsoft has taken a significant step in addressing a critical security vulnerability, CVE-2024-38058, which pertains to a bypass of the BitLocker Device Encryption feature. This flaw poses a risk by allowing potential attackers with physical access to a device to circumvent encryption and access sensitive data. However, the company has recently announced the disabling of a fix intended to mitigate this issue due to complications arising from firmware incompatibility.

Details of the Vulnerability and Response

In a communication released on Wednesday, Microsoft acknowledged the challenges faced by users who applied the initial fix. The company noted, “When customers applied the fix for this vulnerability to their devices, we received feedback about firmware incompatibility issues that were causing BitLocker to go into recovery mode on some devices.” As a result, the fix will be disabled with the rollout of the August 2024 security updates.

For those seeking to safeguard their systems against the CVE-2024-38058 vulnerability, Microsoft recommends following the mitigation measures outlined in the KB5025885 advisory. However, this approach is not without its complexities. Users will now need to engage in a four-stage procedure that necessitates restarting the affected device a total of eight times.

Moreover, Microsoft has issued a caution regarding the application of these mitigations on devices utilizing Secure Boot. Once the mitigation is enabled, it cannot be undone, even if the device is reformatted. The company warns, “After the mitigation for this issue is enabled on a device… it cannot be reverted if you continue to use Secure Boot on that device.” This highlights the importance of understanding the implications and thoroughly testing the process before proceeding.

Recent Updates and Ongoing Issues

In conjunction with this development, Microsoft addressed a known issue that emerged following the July Windows security updates, which inadvertently caused some devices to boot into BitLocker recovery mode. While this situation aligns with the firmware incompatibility that led to the disabling of the CVE-2024-38058 fix, Microsoft has refrained from providing specific details regarding the root cause or the resolution of this issue.

The company has simply advised affected users to install the latest updates for their devices, emphasizing that these updates contain essential improvements and resolutions for various issues, including the recent booting problems. However, no direct connection has been made between this bug and the CVE-2024-38058 vulnerability.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6440327
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1295426
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
498186
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
454503
downloads

News and reviews for Desktop Windows

PC Gamer's Top 2025 Reviews: Games That Made the Cut

PC Gamer reveals top games of 2025, highlighting scoring criteria and surprises in reviews.

Read more

Vulnerability Patched in Triofox Platform Exploited by Hackers

Mandiant reveals n-day attacks on Triofox. Patch now for enhanced security.

Read more

Bazzite: An Alternative to Windows for Gamers

Bazzite offers a gaming-centric OS alternative to Windows 10, appealing to Steam users but with limitations in creative apps and game services.

Read more

Tailside: Cozy Cafe Sim Releases on Steam 2026-01-21

Tailside launches on Steam January 21, 2026. Players manage a cozy café featuring fluffy creatures.

Read more

Resident Evil 4 Remake Hits Lowest Price at $16.79

Resident Evil 4 remake is on sale for $16.79 until 2025-11-16. Enhancements include updated visuals and gameplay. Secure this deal now.

Read more

Discover Hidden Windows 11 Apps Enhancing Productivity

Explore free, overlooked Windows 11 apps boosting productivity in 2025 without ads or upsells.

Read more

Will Glow the Wisp Free on Steam Until 2023-11-11

Will Glow the Wisp, inspired by Xbox classics, is free on Steam briefly, delighting indie game fans.

Read more

Expand PlayStation Games Library on PC with Top Titles

Top PlayStation games now on PC are expanding gaming options with remasters and exclusives.

Read more

Windows XP Revival: Nostalgic Apps Run on Virtual Machine

Windows XP returns via a virtual machine in 2025 to replay 3D Pinball, Movie Maker, and TweakUI.

Read more

Adds Water Simulation in Enshrouded's Wake of the Water Update

Enshrouded's new update introduces dynamic water environments. Explore Veilwater Basin and new combat options now. Available on Steam for $29.99.

Read more