I put together a PoC for a boot manager downgrade attack against BitLocker, building on Microsoft STORM's BitUnlocker research (CVE-2025-48804). Simpler to pull off than Bitpixie in most cases.
The push for TPM+PIN enforcement and SVN-based revocation shall continue!
Repo: https://github.com/garatc/BitUnlocker
All credit to Microsoft STORM for the original research
#BitLocker #infosec #pentesting #WindowsSecurity #physicalaccess
