Microsoft recently fixed a vulnerability in the disk encryption feature in BitLocker , which could be exploited very easily, bypassing it in a matter of seconds.
A disk encryption tool is a very important piece of software for protecting our data, thousands of machines rely on it to protect their users' data, but we should consider that these applications could also be affected by critical flaws.
In September, security researcher James Forshaw , a member of Google 's Project Zero team , discovered two critical vulnerabilities in the driver that the popular encryption tool TrueCrypt installs on Windows systems. The vulnerabilities could be exploited by attackers to gain access to protected data.
BitLocker is another popular disk encryption tool designed by Microsoft and relied on by an incredible number of users to protect their data!
The news, however, is that BitLocker can be bypassed very easily.
According to recent research conducted by Ian Haken from Synopsys, the security feature implemented in BitLocker can be bypassed, and it doesn't even require a sophisticated attacker.
Before this tool, an attacker could simply boot a live Linux distribution onto the disk containing the data and gain access to it. Full-disk encryption starts at boot time, protecting the data with impenetrable encryption.
Haken explained that computers that are connected to domains are more vulnerable to attacks if attackers can disconnect the machine from the network and the domain server cannot be reached. In this attack scenario, the Windows machine uses a local username and password stored in the cache. The researcher discovered a method to access the cached password and modify it. In this way, the attacker is able to bypass the full-disk encryption.
The researcher demonstrated that by creating a fake domain server with the same name, the attacker only had to create a user account with the password the user had previously created. This trick triggers a policy-based password change, at which point it is enough to change the password and log in to the PC using the password set in the cache.
Microsoft as low priority as its exploitation requires specific conditions.
