Microsoft has confirmed a vulnerability in Windows Recovery Environment that can let an attacker with physical access bypass ...