Home / Series / Chaos Communication Congress / Aired Order / Season 38 / Episode 104

Windows BitLocker: Screwed without a Screwdriver

Ever wondered how Cellebrite and law enforcement gain access to encrypted devices without knowing the password? In this talk, we’ll demonstrate how to bypass BitLocker encryption on a fully up-to-date Windows 11 system using Secure Boot. We’ll leverage a little-known software vulnerability that Microsoft has been unable to patch since 2022: bitpixie (CVE-2023-21563). We'll live-demo the exploit, and will walk through the entire process—from the prerequisites and inner workings of the exploit to why Microsoft has struggled to address this flaw. We'll also discuss how to protect yourself from this and similar vulnerabilities.

English
  • Originally Aired December 28, 2024
  • Runtime 60 minutes
  • Production Code 816
  • Created January 1, 2025 by
    r4m3u5
  • Modified January 1, 2025 by
    r4m3u5