CVE-2025-21210
Windows BitLocker Information Disclosure Vulnerability
Description
Windows BitLocker Information Disclosure Vulnerability
INFO
Published Date :
Jan. 14, 2025, 6:15 p.m.
Last Modified :
June 17, 2026, 8:42 a.m.
Remotely Exploit :
No
Source :
[email protected]
Affected Products
The following products are affected by CVE-2025-21210
vulnerability.
Even if cvefeed.io is aware of the exact versions of the
products
that
are
affected, the information is not represented in the table below.
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | MEDIUM | [email protected] |
Solution
- Apply the latest Windows security updates.
- Ensure BitLocker is configured correctly.
- Review access controls for sensitive data.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2025-21210.
| URL | Resource |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21210 | Patch Vendor Advisory |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2025-21210 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2025-21210
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2025-21210 vulnerability anywhere in the article.
-
tripwire.com
Tripwire Patch Priority Index for January 2025
Tripwire's January 2025 Patch Priority Index (PPI) brings together important vulnerabilities for Microsoft.First on the list are patches for the Microsoft office platform, including Word, Access, Visi ... Read more
-
The Hacker News
3 Actively Exploited Zero-Day Flaws Patched in Microsoft's Latest Security Update
Microsoft kicked off 2025 with a new set of patches for a total of 161 security vulnerabilities across its software portfolio, including three zero-days that have been actively exploited in attacks. O ... Read more
-
krebsonsecurity.com
Microsoft: Happy 2025. Here’s 161 Security Updates
Microsoft today unleashed updates to plug a whopping 161 security vulnerabilities in Windows and related software, including three “zero-day” weaknesses that are already under active attack. Redmond’s ... Read more
-
The Cyber Express
Microsoft January 2025 Patch Tuesday: 8 Zero-Days, 3 Actively Exploited
Microsoft’s Patch Tuesday update for January 2025 patches 159 vulnerabilities, including eight zero-days, three of which are being actively exploited. The Microsoft January 2025 Patch Tuesday release ... Read more
-
tripwire.com
VERT Threat Alert: January 2025 Patch Tuesday Analysis
Today’s VERT Alert addresses Microsoft’s January 2025 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-1139 as soon as coverage is completed.In ... Read more
-
Help Net Security
Microsoft fixes actively exploited Windows Hyper-V zero-day flaws
Microsoft has marked January 2025 Patch Tuesday with a hefty load of patches: 157 CVE-numbered security issues have been fixed in various products, three of which (in Hyper-V) are being actively explo ... Read more
-
BleepingComputer
Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws
Today is Microsoft's January 2025 Patch Tuesday, which includes security updates for 159 flaws, including eight zero-day vulnerabilities, with three actively exploited in attacks.This Patch Tuesday al ... Read more
The following table lists the changes that have been made to the
CVE-2025-21210 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'Microsoft', 'product': 'Windows 10 Version 1507', 'versions': [{'status': 'affected', 'version': '10.0.10240.0', 'lessThan': '10.0.10240.20890', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 10 Version 1607', 'versions': [{'status': 'affected', 'version': '10.0.14393.0', 'lessThan': '10.0.14393.7699', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 10 Version 1809', 'versions': [{'status': 'affected', 'version': '10.0.17763.0', 'lessThan': '10.0.17763.6775', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 10 Version 21H2', 'versions': [{'status': 'affected', 'version': '10.0.19044.0', 'lessThan': '10.0.19044.5371', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'ARM64-based Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 10 Version 22H2', 'versions': [{'status': 'affected', 'version': '10.0.19045.0', 'lessThan': '10.0.19045.5371', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'ARM64-based Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 11 version 22H2', 'versions': [{'status': 'affected', 'version': '10.0.22621.0', 'lessThan': '10.0.22621.4751', 'versionType': 'custom'}], 'platforms': ['ARM64-based Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 11 version 22H3', 'versions': [{'status': 'affected', 'version': '10.0.22631.0', 'lessThan': '10.0.22631.4751', 'versionType': 'custom'}], 'platforms': ['ARM64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 11 Version 23H2', 'versions': [{'status': 'affected', 'version': '10.0.22631.0', 'lessThan': '10.0.22631.4751', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 11 Version 24H2', 'versions': [{'status': 'affected', 'version': '10.0.26100.0', 'lessThan': '10.0.26100.2894', 'versionType': 'custom'}], 'platforms': ['ARM64-based Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2008 R2 Service Pack 1', 'versions': [{'status': 'affected', 'version': '6.1.7601.0', 'lessThan': '6.1.7601.27520', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2008 R2 Service Pack 1 (Server Core installation)', 'versions': [{'status': 'affected', 'version': '6.1.7601.0', 'lessThan': '6.1.7601.27520', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2008 Service Pack 2', 'versions': [{'status': 'affected', 'version': '6.0.6003.0', 'lessThan': '6.0.6003.23070', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2008 Service Pack 2 (Server Core installation)', 'versions': [{'status': 'affected', 'version': '6.0.6003.0', 'lessThan': '6.0.6003.23070', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2012', 'versions': [{'status': 'affected', 'version': '6.2.9200.0', 'lessThan': '6.2.9200.25273', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2012 (Server Core installation)', 'versions': [{'status': 'affected', 'version': '6.2.9200.0', 'lessThan': '6.2.9200.25273', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2012 R2', 'versions': [{'status': 'affected', 'version': '6.3.9600.0', 'lessThan': '6.3.9600.22371', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2012 R2 (Server Core installation)', 'versions': [{'status': 'affected', 'version': '6.3.9600.0', 'lessThan': '6.3.9600.22371', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2016', 'versions': [{'status': 'affected', 'version': '10.0.14393.0', 'lessThan': '10.0.14393.7699', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2016 (Server Core installation)', 'versions': [{'status': 'affected', 'version': '10.0.14393.0', 'lessThan': '10.0.14393.7699', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2019', 'versions': [{'status': 'affected', 'version': '10.0.17763.0', 'lessThan': '10.0.17763.6775', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2019 (Server Core installation)', 'versions': [{'status': 'affected', 'version': '10.0.17763.0', 'lessThan': '10.0.17763.6775', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2022', 'versions': [{'status': 'affected', 'version': '10.0.20348.0', 'lessThan': '10.0.20348.3091', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'versions': [{'status': 'affected', 'version': '10.0.25398.0', 'lessThan': '10.0.25398.1369', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2025', 'versions': [{'status': 'affected', 'version': '10.0.26100.0', 'lessThan': '10.0.26100.2894', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2025 (Server Core installation)', 'versions': [{'status': 'affected', 'version': '10.0.26100.0', 'lessThan': '10.0.26100.2894', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2025-21210', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-01-15T21:21:39.457313Z'} -
Initial Analysis by [email protected]
Jan. 27, 2025
Action Type Old Value New Value Added CWE NIST NVD-CWE-noinfo Added CPE Configuration OR *cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.10240.20890 *cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.10240.20890 *cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.14393.7699 *cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.14393.7699 *cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.17763.6775 *cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.17763.6775 *cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.19044.5371 *cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.19045.5371 *cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.22621.4751 *cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.22631.4751 *cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.26100.2894 *cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* *cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* *cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* *cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* *cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.14393.7699 *cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.17763.6775 *cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.20348.3091 *cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.25398.1369 *cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.26100.2894 Changed Reference Type https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21210 No Types Assigned https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21210 Patch, Vendor Advisory -
New CVE Received by [email protected]
Jan. 14, 2025
Action Type Old Value New Value Added Description Windows BitLocker Information Disclosure Vulnerability Added CVSS V3.1 AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Added CWE CWE-636 Added Reference https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21210