DEF CON 33 -BitUnlocker: Leverage Windows Recovery to Extract BitLocker Secrets - Leviev, Ben Simon

DEF CON 33 -BitUnlocker: Leverage Windows Recovery to Extract BitLocker Secrets - Leviev, Ben Simon

Source: YouTube · DEFCONConference · published Nov 3, 2025 · 38:27

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Microsoft researchers discovered vulnerabilities in the Windows Recovery Environment (WinRE) that allowed bypassing BitLocker protection and extracting encrypted secrets 0:03.

Key Takeaways:
• Researchers found WinRE presents a significant attack surface as it can boot independently while BitLocker-protected volumes remain in auto-unlock state 3:55
• Multiple vulnerabilities were identified including Boot SDI file manipulation that allowed loading untrusted WIM files while keeping the OS volume unlocked 12:50
• Recovery Agent XML configuration could be abused to execute trusted applications like TT tracer to gain shell access with BitLocker protection disabled 16:04
• BCD parsing vulnerability allowed tricking WinRE into using attacker-controlled configuration by exploiting volume iteration order 29:00
• These vulnerabilities could be chained to completely disable BitLocker protection using the Push Button Reset feature 33:19

All discovered vulnerabilities were fixed in July's Patch Tuesday, and researchers recommend enabling TPM+PIN for enhanced BitLocker security 37:02.

Sources:

  • 0:03 Introduction to "BitLocker unlocker leveraging Windows recovery"
  • 3:55 WinRE attack surface explanation
  • 12:50 Boot SDI vulnerability demonstration
  • 16:04 Recovery Agent XML exploitation
  • 29:00 BCD parsing vulnerability details
  • 33:19(

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Okay, so hello everyone. Thank you for joining us today. Welcome to our talk beat unlocker leveraging Windows recovery to extract Bit Locker secrets. >> Can you hear me? >> Let's go. Today we'll take you inside our journey of attacking and securing Bit Locker. We show you how we found and exploited and fixed new vulnerabilities in the Windows recovery environment that allowed extracting all the Bit Locker protected secrets. But just before we dive in, a quick introduction. So my name is Alon and here with me on stage is Nanel. We're both security researchers working with the security testing and offensive re research team at Microsoft also known as storm. Our expertise is in vulnerability research focused on everything that happens before the operating system fully loads covering the vario…