Windows 10: Out-of-band update ends Bitlocker recovery

Microsoft has published a solution for the recently occurred Bitlocker problem in Windows 10. An out-of-band update fixes the mistakes that occurred after the May patch. Affected systems repeatedly showed recovery screens.
Solution for Bitlocker problems published
The company now has that Update KB5061768 as an out-of-band update Provided that the version number increases to 19045,5856 and should fix the problem. According to Microsoft, corporate systems with special hardware configuration were particularly affected. The problem occurred, among other things, at Intel VPro processors of the 10th or later generation that Intel Trusted Execution Technology (TXT) activated. Private users were hardly affected by this problem because they usually do not use VPRPR processors.
Serious effects on affected systems
According to the information that Microsoft provides via the Release Health Dashboard, the error led to the lsass.exe process unexpectedly ended, which caused an automatic repair. If the bitlocker was activated, users had to enter their recovery key. This could result in a frustrating endless loop, in which users had to enter the recovery key again after each restart. The problem was particularly noticeable in companies, where systems are managed via System Center Configuration Manager (SCCM) or Windows Server Update Services (WSUS).
Fixed: A well-known problem on devices with an activated Intel Trusted Execution Technology (TXT) on Intel VPRO processors of the 10th generation or higher. On these systems, the installation of the Windows Security Update (KB5058379) of May 13, 2025 can lead to the LSASS process (Local Security Authority Authority Subsystem Service) unexpectedly ended, which triggers automatic repair, which is challenging the Bitlocker recovery key. Microsoft Support
Fast problem solving through Microsoft
The new update KB5061768 is only over the Microsoft Update Catalog Available and is available for various system architectures-both for 64-bit and 32-bit systems as well as for arm-based devices. Microsoft recommends all affected users to install the update as soon as possible. As a temporary solution, the deactivation of the “Intel Trusted Execution Technology” in BIOS had previously proven itself.
This measure is no longer necessary after installing the update and can be withdrawn. For systems that are located in the Bitlocker recovery loop, Microsoft recommends first entering the recovery key, then starting the system normally and then installing the update in order to avoid further problems.