Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Automox: BitLocker Bypass, Secure Boot Expiration & Linux PrivEsc

Automox
07/23/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


We've made it to the seventh month of the year already. And we're here on this wonderful Tuesday to talk about some amazing fixes Microsoft has released in their products on this Patch Tuesday. I'm Tom, thanks for joining. It's been a very long time since I've been on this podcast, but I'm happy to be filling in for Ryan while he's on vacation, making the rest of us jealous. So, yeah, definitely an interesting Patch Tuesday. We got some good things to talk about here in these release notes. And the first one that we kind of ran through internally, is more BitLocker bypasses. And specifically for this one, CVE-2025-48001, which is kind of a race condition in BitLocker that allows kind of a physical attack on devices, which I thought was really, really, really interesting. But, you know, I'm curious, Seth, what are your thoughts on this one specifically? Yeah, so like you said, this one is a physical attack. You actually have to have the device in front of you. And so for this one, basically, what's broken here is BitLocker is, it's like a pre-boot process. So the system checks the protection state. So that would be like what the TPM folds. And then it'll check like the boot drives, things like that. And then after that check happens, it releases that to, it actually releases it to RAM, and then it can then decrypt the drive. So what's happening here is a time of check and a time of use race condition. So again, as I was saying, like, so the BitLocker boot environment will verify the TPM values, the secure boot state and the required filter drives. And then after that check happens is the time of use. So immediately after that, it unseals the full volume encryption key, and then it places it in memory for it to use. So what happens here is the vulnerability will arise because the attacker with direct access to that hardware. So, you know, again, this is going to affect lost or stolen laptops. And this primarily affects, well, it's anybody that uses BitLocker. But, you know, a lot of corporations are using BitLocker and are relying on that to keep their device secure in the event it gets lost or stolen. So that's how this attack works. So basically, what would happen is, you know, you have an adversary that would steal a laptop and have physical control of that. And, you know, it's a pirate powered offer in Hibernate. They would attach what's called a DMA capable device or swap the drives registry or filter drive configuration during the bootloader. So that's kind of how it works. And then from there, they bypass encryption, they have access to that key. So from there, they can do anything. They can data exfil, they can try PrivEsc. There's a ton of different things they can do. I mean, they have full access to the hard drive at that point, completely unencrypted. So to kind of mitigate that, you can do other things in the BIOS. You can do like a pre-boot pin, where before all of those checks even happen, you have to put in a pin or a password. You know, you can tighten up physical security. And then, of course, patching will hopefully fix this. So yeah, that's basically it on that one. Yeah, it's absolutely crazy to me how low this is rated, right? Because you make such a great point about lost or stolen laptops, because often those things don't get wiped, right? Because they never connect to the internet again. They're just kind of stolen. And then placed somewhere in a wheelhouse and overseas to another country to be kind of stored until vulnerabilities like this happen. And then they can kind of bypass BitLocker with a physical device at hand and then do what they may with the device after the contents of the hard drive are decrypted, right? So to me, this feels like one of those like, yeah, it's low and they're kind of downplaying. Well, the attack vector, you got to have physical access to the device. But no one really cares about stolen devices these days. No one's really retrieving them. They're mostly just writing it off and then buying the employee a new device, right? And completely relying on built-in features within Mac or within Windows to protect the confidentiality of these drives. So it's crazy how low this is rated, given, I think, the implications for everyone involved. So yeah, really, really interesting. Speaking of booting, secure boot certificates expire June of next year, which is quite the interesting timing and a little bit of Microsoft giving us a one-year heads up, which I think is probably not enough time, given how this industry works. And I'm real curious, Cody, what your take on this one is specifically. Yeah, it's going to be interesting. So basically, everything that's not a Copilot Plus PC released this year, I think as of April this year, is going to be affected by this. So you will have to go. And so there's two routes to this. One is that you are an enterprise customer, and you have to be opted into updates. Otherwise, you will not get the update for some reason. The second route is for everybody who's not enterprise, and you have to kind of follow the same little workflow logic of you have to go edit your registry keys, and you have to set a specific key to a weird D value or D word value, which is like 5944, which gets you opted into the auto patch service. The other concern with all of this is so these are all expiring, and it seems like the only way that they're willing to update devices is if you are also sending diagnostic data. So if you're worried about sending, like telemetry back to Microsoft, it gets even harder to try to update your secure boot stuff. But I don't know, I guess the risk is quite large, though, because you won't be able to install secure boot updates, you won't be able to trust third party software after June of next year for most in October for a couple of them. Yeah. And then you won't be able to update your boot manager after October. So it's quite the litany of problems if you cannot get this solved. Luckily, they are making it somewhat easy to do. And they do have a page that you can go, you can go download their app, and it'll let you know if you're already opted in or if everything's set up correctly. So it'll do the registry key checks and everything for you. And I believe they've already started rolling out updates as of last month. And they are still going to release secure boot updates for Windows 10 after October 2025, because I believe October of this year is when they stop support entirely for Windows 10. But they have committed to updating everything for that as well. Yeah, the other thing with that secure boot, that's kind of like your first line of defense against boot kits, too. So after that certificate expires, like that leaves anything that's not updated at risk. Oh, yeah. And another one to think of, too, is if you currently have secure boot disabled, you will also not be able to get the updated certificates. So they're recommending that you turn secure boot on to get the updates. And then if you want it off, to turn it back off. So it's kind of a mess. And yeah, I agree. One year in enterprise stuff is just not long enough. So I think we're going to see a lot of physical devices just have secure boot issues. And we're probably going to see a lot of people just unable to use third party software in about a year. Yeah. I mean, outside of the enterprise, right? I just Windows is still king everywhere. And yeah, I just can't imagine like walking your grandma through this nasty problem, right? Like it just there's got to be an easier way here. And I appreciate all the guidance Microsoft provided in their article and those kind of things. But these are the things I think about is like, okay, cool. Well, most devices in the enterprise are MDM and we could push down like a group policy or something, or you could write an automax worklet or whatever to manage this kind of registry value. But, you know, if your grandma, that computer that your kids use or whatever, you know, do they even know? Do they even care? Are there going to is there going to be pop ups, right? That could walk somebody through it on devices that are not enterprise managed. If you see pop ups, don't click them. Never click a pop up. That's so true. It's so true. You know, look, Tom, it's 2025. If your grandmother doesn't know how to edit the registry yet. It's true. Maybe Copilot can do that for us. We can just ask, can you update this registry value? So I'm ready for a secure boot, you know, missed opportunity by Microsoft. You know, if you're asking me right here, Copilot use, boom, done, right? Let them know. Absolutely. Cool. Yeah. So just to summarize all the Microsoft ones that we found interesting, obviously BitLocker, right? Make sure you're keeping that up and keep an eye out on these expiring certificates in secure boot as that rolls out before it expires in June of next year. Couple other things that really piqued our interest this these past couple of weeks, right? Is CVE 2025-32463, which is another true vulnerability. And yeah, it's just it feels like another one of those Linux things where, right, the hardest, the easy part is getting on the host, right? And when you're a low priv user in Linux, a lot of times you can't really do much, right? People do in the modern world usually do a pretty good job of like, you know, only running things as low priv users or applications like Nginx or Apache do a good job of, you know, reducing capabilities down to like a user level instead of running as root. But, you know, getting on a getting on a box and finding, you know, an outdated root or an outdated sudo is a really, really, I think, easy find these days, and especially in, you know, outside of the enterprise and like CTF land freight, all these things, all of these things always remind me of that, right? Like a hack the box type machine where you got to exploit this single vulnerability. But, you know, I'm curious to your thoughts on this one, Cody, as well. Yeah, so this one's this one's interesting because the vulnerability is in between where it starts to pivot the root and unpivot the root in the true binary. So for one, you should never rely on true as a security mechanism. It has so many problems that, you know, it's been exploited many times over. But it is a good part of the you know, the security onion, I guess. So, but in between, in between the parts where it starts to pivot the root ID of the virtual changer, it makes a call out to NS switch. So one of the big problems is that you can shoot into a directory and you can overwrite the NS switch and that allows you to load shared libraries. So you can do like completely complete shared objects. And I think the the demo that they have for like the POC that they have involves just calling a password at the password. So it's able to dump the entirety of password into the rooted binary environment. But it's pretty trivial to make it do anything else. If you I'm sure will link the article to it near the bottom of the article, you can see the call chain. And inside there, you can just chain out to as many DLLs as you want, it looks like. And then kind of circumvents the PAM approval as well, which was another interesting one that I saw. And, yeah, I mean, being able to do this is very trivial. It's like 20 lines of code or less, I think. It ends up being, well, actually, the POC itself is eight lines or nine lines of code. So, yeah, in nine lines, you've got root. Amazing, right? Just amazing. And these things too, you know, sometimes these things can lead to like container breakouts or other similar, you know, attack vectors when you're operating in like a containerized environment as so many enterprises use today. And, you know, a lot of the industry doesn't necessarily think about these kind of deep kernel exploits, right, of containers and Kubernetes and all these things because they're, well, it's in a container, it's fine, right? But the reality is, it's like everything is shared underneath, right, in a lot of senses. So, like NS switch and all those commands still apply in a containerized environment. So, just because you're running a container doesn't necessarily mean you're safe from this. So, you know, keep an eye out for a lot of those things. But yeah, just another, all these tools that we just trust, right? Well, you know, Sudo and Trude and all these kind of security. It's funny because we've talked only about security kind of controls, right, in this podcast so far. BitLocker and Secure Boot and all these tools are often just as exploited as, you know, Word or other type tools, right? So, it's the attack services always there ever growing in the industry. Speaking of attack surface, right, the one final thing we wanted to talk about today was this zip trick, which unfortunately, you know, to me feels really just weird, right? Like all these zip tricks and all these polymorphic attacks that you see sometimes, you know, these texts and JPEGs and those sort of things are always interesting, right? How you can abuse a trusted system like a zip file or other similar things and, you know, bypass security measures or exploit systems or do those kind of things. You know, sometimes it's a little researchy when you're reading through these exploit chains. But I do think that, you know, something like this one is probably a little less researchy and a little more practical in the day-to-day. And I'm curious to y'all's thoughts on that one. Yeah, this one's interesting. They take the approach of not polymorphic, but schizophrenic zip, that's what they're calling it. So, yeah, so the way that I'm understanding it is you're basically modifying part of like the end of central directory record at the top. And you're hiding files at the beginning of central directory, but you're modifying the offset. So you're only showing a specific subset of files. And I guess one of the ways or one of the technical demonstrations they did were with invoices. So they're showing you one invoice and like this PDF inside the zip. And you go to pay the invoice, I guess. And it's sending off a separate PDF file to a different company with all of your bank account information. So, yeah, lots of weird stuff to this one. But it seems very, I mean, it's very trivial. It's another trivial one. You know, you're just modifying the header or the zip header. And that's it. Like with this one, when you and then like, because you would just create a directory with both benign and malicious files. Like that's pretty basic. Yeah, absolutely. The other big one too is a lot of the hidden files can be executed without, you know, you ever even seeing them. So while it's being skipped in like the view state. So if you go to look at the zip, like the zip directory, you don't see the files in there. But as you're unzipping it, it can execute stuff inside that hidden area of the central directory. Yeah, who's going to look at, you know, what's unzipping versus what they previewed, right? Like, it's just one of those areas in the modern workforce. We just blindly trust, right? Like a zip file. No one knows that it can be used for like these kind of abuse mechanisms. So yeah, just a great place to kind of attack, you know, attack a company, whether you're doing it for a malicious intent, or maybe like an academic type of red team exercise, like this article shows specifically. It's just, you know, everything can be abused and all of these trusted systems we have in the modern workforce is right for exploitation, right? And that's the unfortunate reality of security. You know, you always got to be paranoid about everything. Yeah. Oh, cool. Oh, the other interesting part of it was, I guess one of the things they noticed is that it will detect the software stack that you're on and change the visibility in the central directory based on that. So like they're talking about attempting to target somebody who approves invoices, so they'll approve the correct one. So it looks correct, because obviously they're going to be able to validate it. But when your finance team goes to pay it, you know, your finance team has no idea about your IT stack, right? So it's detecting that they're running like payment software or whatever, QuickBooks 2003, who knows? And that's when it'll change the visibility of the file. So I thought that was interesting, too. Nice. Yeah, absolutely. And that's where the schizophrenic part comes in. I mean, it's true to name, true to name for sure. Cool. Well, that's kind of all we had today. We appreciate your continued support as we ramble on about Microsoft's latest release notes and some other interesting things we find layering around the web. Happy July, everybody. And thank you all for tuning in to this episode of Fix Tuesday.

TL;DR

  • CVE-2025-48001 enables physical attackers to bypass BitLocker encryption through a race condition that exposes decryption keys in memory during boot, posing significant risk to lost or stolen enterprise laptops despite low CVSS rating
  • Microsoft secure boot certificates expire June 2026, requiring manual registry edits for consumer devices and explicit opt-in for enterprise customers, with failure to update eliminating bootkit protection and third-party software trust
  • CVE-2025-32463 allows Linux privilege escalation to root in nine lines of code by exploiting chroot's NS switch calls, affecting both traditional servers and containerized environments where kernel components are shared
  • Schizophrenic ZIP exploit manipulates central directory records to show different files during preview versus extraction, enabling targeted social engineering attacks that detect software environments and execute hidden payloads
  • All four vulnerabilities demonstrate how trusted security controls — encryption, secure boot, privilege separation, and file formats — remain vulnerable to sophisticated attacks requiring defense-in-depth strategies

BitLocker Physical Attack Vulnerability

The episode opens with analysis of CVE-2025-48001, a race condition vulnerability in Microsoft BitLocker that enables physical attackers to bypass full-disk encryption on lost or stolen devices. The flaw exists in the time window between when BitLocker verifies TPM values and secure boot state and when it unseals the encryption key into memory. Attackers with physical access can attach DMA-capable devices or modify registry configurations during bootloader execution to intercept the decryption key. Despite requiring physical access, the hosts emphasize this represents a significant risk for enterprise environments where stolen laptops are typically written off rather than recovered, leaving encrypted data vulnerable to extraction. Mitigation strategies include implementing pre-boot PINs, tightening physical security controls, and applying Microsoft's July patches.

Secure Boot Certificate Expiration Crisis

Microsoft has announced that secure boot certificates will expire in June 2026, affecting all Windows devices except Copilot Plus PCs released after April 2025. The update process requires enterprise customers to opt into updates explicitly, while consumer users must manually edit registry keys to enable automatic patching. The hosts express concern about the one-year timeline being insufficient for enterprise deployment cycles and highlight the complexity of requiring diagnostic data sharing for certificate updates. Devices that fail to update will lose the ability to install secure boot updates, trust third-party software, and update boot managers after October 2026. This creates a significant security gap as secure boot serves as the primary defense against bootkit attacks. The discussion emphasizes the challenge of communicating this technical requirement to non-enterprise users who lack IT support.

Linux Privilege Escalation via chroot

CVE-2025-32463 represents a privilege escalation vulnerability in the Linux chroot utility that allows low-privileged users to gain root access through manipulation of NS switch configuration during the root pivot process. The exploit leverages a window in chroot's execution where it calls out to NS switch before completing privilege transitions, enabling attackers to load malicious shared libraries. The proof-of-concept demonstrates root access can be achieved in approximately nine lines of code, making this a highly accessible attack vector. The hosts note this vulnerability extends beyond traditional server environments to containerized deployments, where shared kernel components mean container isolation doesn't protect against this class of exploit. The discussion reinforces that security controls like chroot and sudo, while valuable as defense-in-depth measures, should never be relied upon as primary security mechanisms.

Schizophrenic ZIP File Exploit

Researchers have demonstrated a novel ZIP file manipulation technique that presents different file contents during preview versus extraction, enabling sophisticated social engineering attacks. The exploit modifies the end of central directory record and offset values to hide malicious files in the beginning of the central directory while displaying only benign files during inspection. The technique can detect the software stack in use and dynamically adjust file visibility based on the target environment — for example, showing legitimate invoices to approvers while presenting fraudulent payment information to finance teams using different software. Hidden files can execute during extraction without ever appearing in directory listings, bypassing user awareness entirely. The hosts emphasize this represents a practical attack vector against trusted file formats that users rarely scrutinize beyond initial preview, making it effective for both malicious campaigns and red team exercises.

Chapters

0:00 - Introduction & July Patch Tuesday Overview
1:03 - BitLocker Physical Attack Vulnerability
5:47 - Secure Boot Certificate Expiration
11:37 - Linux chroot Privilege Escalation
16:13 - Schizophrenic ZIP File Exploit
20:53 - Closing Remarks

Key Quotes

1:32 "You actually have to have the device in front of you. And so for this one, basically, what's broken here is BitLocker is, it's like a pre-boot process. So the system checks the protection state. So that would be like what the TPM folds. And then it'll check like the boot drives, things like that. And then after that check happens, it releases that to, it actually releases it to RAM, and then it can then decrypt the drive."
4:34 "It's absolutely crazy to me how low this is rated, right? Because you make such a great point about lost or stolen laptops, because often those things don't get wiped, right? Because they never connect to the internet again. They're just kind of stolen. And then placed somewhere in a wheelhouse and overseas to another country to be kind of stored until vulnerabilities like this happen."
9:18 "One year in enterprise stuff is just not long enough. So I think we're going to see a lot of physical devices just have secure boot issues. And we're probably going to see a lot of people just unable to use third party software in about a year."
13:08 "You should never rely on true as a security mechanism. It has so many problems that, you know, it's been exploited many times over. But it is a good part of the you know, the security onion, I guess."
14:44 "The POC itself is eight lines or nine lines of code. So, yeah, in nine lines, you've got root."
19:06 "Who's going to look at, you know, what's unzipping versus what they previewed, right? Like, it's just one of those areas in the modern workforce. We just blindly trust, right? Like a zip file. No one knows that it can be used for like these kind of abuse mechanisms."

FAQ

How can organizations protect against the BitLocker physical attack vulnerability?

Organizations should implement pre-boot PINs or passwords that execute before BitLocker's TPM checks, apply Microsoft's July 2025 patches, and strengthen physical security controls for devices. The vulnerability requires physical access to exploit, so preventing device theft and ensuring rapid remote wipe capabilities for lost devices are critical mitigation strategies.

What happens if Windows devices don't update secure boot certificates before expiration?

Devices that fail to update will lose the ability to install secure boot updates after June 2026, cannot trust third-party software, and cannot update boot managers after October 2026. This eliminates protection against bootkit attacks and creates significant security gaps. Enterprise customers must opt into updates, while consumer users must manually edit registry keys to enable automatic patching.

Does running applications in containers protect against the Linux chroot privilege escalation?

No, containerization doesn't eliminate this risk because containers share underlying kernel components like NS switch. The vulnerability exists at the kernel level, so even containerized environments remain vulnerable if the host system runs affected versions of chroot. Organizations should patch the vulnerability and avoid relying on chroot as a primary security control.


Categories:
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Endpoint Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Vulnerability Management
  • Endpoint Management
  • Technical Deep Dive
  • Threat Intelligence
  • BitLocker encryption bypass
  • Secure boot certificate management
  • Linux privilege escalation
  • ZIP file exploits
  • Physical security attacks
  • Container security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Automox: BitLocker Bypass, Secure Boot Expiration & Linux PrivEsc

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    06

                    Mitigating Risks of Sensitive Data Exposure in AI Platforms

                    08/06/202604:00 AM ET
                    • Aug
                      07

                      Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift

                      08/07/202611:00 AM ET
                      • Aug
                        19

                        Becoming Agent Ready: Insights and Strategies with Cyera

                        08/19/202612:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Mitigating Risks of Sensitive Data Exposure in AI Platforms
                          https://www.truthinit.com/index.php/channel/2058/mitigating-risks-of-sensitive-data-exposure-in-ai-platforms/
                        • 08/07/2026
                          11:00 AM
                          08/07/2026
                          Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-evolving-triage-agent-that-learns-each-shift/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version