CVE Vulnerabilities

CVE-2025-21210

Not Failing Securely ('Failing Open')

Published: Jan 14, 2025 | Modified: Jan 27, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Windows BitLocker Information Disclosure Vulnerability

Weakness

When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

Affected Software

NameVendorStart VersionEnd Version
Windows_10_1507Microsoft*10.0.10240.20890 (excluding)
Windows_10_1607Microsoft*10.0.14393.7699 (excluding)
Windows_10_1809Microsoft*10.0.17763.6775 (excluding)
Windows_10_21h2Microsoft*10.0.19044.5371 (excluding)
Windows_10_22h2Microsoft*10.0.19045.5371 (excluding)
Windows_11_22h2Microsoft*10.0.22621.4751 (excluding)
Windows_11_23h2Microsoft*10.0.22631.4751 (excluding)
Windows_11_24h2Microsoft*10.0.26100.2894 (excluding)
Windows_server_2008Microsoft–sp2 (including)–sp2 (including)
Windows_server_2008Microsoftr2-sp1 (including)r2-sp1 (including)
Windows_server_2012Microsoft- (including)- (including)
Windows_server_2012Microsoftr2 (including)r2 (including)
Windows_server_2016Microsoft*10.0.14393.7699 (excluding)
Windows_server_2019Microsoft*10.0.17763.6775 (excluding)
Windows_server_2022Microsoft*10.0.20348.3091 (excluding)
Windows_server_2022_23h2Microsoft*10.0.25398.1369 (excluding)
Windows_server_2025Microsoft*10.0.26100.2894 (excluding)

Potential Mitigations

References