Home Cyber Security News New Windows BitLocker Zero-Day Bypasses Drive Encryption

New Windows BitLocker Zero-Day Bypasses Drive Encryption

0
Windows BitLocker Zero-Day

A newly disclosed Windows zero-day vulnerability called YellowKey is raising alarms across the cybersecurity community for its ability to bypass BitLocker encryption and expose data on protected drives without requiring the victim’s recovery key.

Published by researcher Nightmare-Eclipse on GitHub, YellowKey targets Windows 11, Windows Server 2022, and Windows Server 2025.

Independent researcher Kevin Beaumont confirmed the exploit is valid, lending immediate credibility to the disclosure.

At the time of reporting, Microsoft had not issued a patch, making this an active, unmitigated zero-day.

BitLocker is widely regarded as a last line of defense when a device falls into unauthorized hands. YellowKey directly challenges that assumption, and the security community is paying close attention.

Windows BitLocker Zero-Day

YellowKey does not crack BitLocker’s encryption algorithm itself. Instead, the weakness lives inside the Windows Recovery Environment (WinRE), where a trusted recovery component can be abused to unlock access in ways defenders never anticipated.

The attack relies on specially crafted files placed on a USB device. A second documented variant writes those files directly to the EFI system partition, which sits outside BitLocker’s protection boundary by design.

Once the system reboots into recovery mode, the vulnerable WinRE component parses the file structure and opens a shell with full access to the BitLocker-protected drive.

Security researcher Will Dormann highlighted a deeper concern: an FsTx log on removable media appeared capable of modifying files on a separate volume when replayed by WinRE.

This points to a potential flaw in how Windows recovery handles cross-volume NTFS transaction replay, and the true security impact of YellowKey could extend well beyond the BitLocker bypass itself.

GreenPlasma Windows CTFMON Arbitrary Section Creation  (Source: Github)

Adding to the risk, the original researcher claims a variant exists that works even in TPM-plus-PIN environments, though that version has not been publicly released.

Some reports suggest that a BitLocker PIN combined with a BIOS password may reduce exposure, but no officially documented mitigation has been confirmed.

Windows 10 was not reported as affected in the same manner, suggesting the flaw is tied specifically to the newer WinRE behavior introduced in Windows 11 and recent server editions, not to every BitLocker deployment across Microsoft’s product line.

YellowKey did not arrive alone. Nightmare-Eclipse simultaneously released GreenPlasma, a separate Windows vulnerability involving CTFMON and arbitrary section creation that could enable local privilege escalation on Windows 11, Server 2022, and Server 2025.

Together, these disclosures form a dangerous pairing: an attacker could use YellowKey to access an encrypted drive and chain GreenPlasma to escalate privileges within the same session.

This is not Nightmare-Eclipse’s first rodeo. The researcher previously published BlueHammer, RedSun, and UnDefend tools that security firms later linked to real-world intrusion activity.

That history shows how quickly public exploit research moves from a GitHub repository into active operational abuse.

For defenders, YellowKey is a critical reminder: full-disk encryption alone cannot protect a device if recovery paths, removable media access, and physical security controls are left exposed.

Organizations running Windows 11 or affected server platforms should urgently review BitLocker protector configurations, restrict WinRE access, enforce physical security policies, and monitor Microsoft’s advisory channels for an official patch.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version