A cybersecurity researcher has published proof-of-concept (PoC) exploits for two unpatched Microsoft Windows vulnerabilities named YellowKey and GreenPlasma, which are a BitLocker bypass and a privilege-escalation flaw. Known as Chaotic Eclipse or Nightmare Eclipse, the researcher describes the BitLocker bypass issue as functioning like a backdoor because the vulnerable component is present only in the Windows Recovery Environment (WinRE), which is used to repair boot-related issues in Windows. The latest exploits follow the researcher's previous disclosure of the BlueHammer (CVE-2026-33825) and RedSun (no identifier) local privilege escalation (LPE) as zero-day flaws, both of which began to be exploited in the wild shortly after being publicly disclosed. As in previous cases, the researcher stated that the decision to publicly disclose the YellowKey and GreenPlasma vulnerabilities, along with guidance on how to leverage them, was driven by dissatisfaction with Microsoft’s handling of bug reports. Chaotic Eclipse, or Nightmare-Eclipse on GitHub, said that they will keep leaking exploits for undocumented Windows vulnerabilities, even promising “a big surprise” for the next Patch Tuesday. The researcher says that YellowKey is a BitLocker bypass that affects Windows 11 and Windows Server 2022/2025. It involves placing specially crafted ‘FsTx’ files on a USB drive or EFI partition, rebooting into WinRE, and triggering a shell by holding down the CTRL key. Additionally, the BitL...
Windows BitLocker zero-day gives access to protected drives, PoC released
BleepingComputer
·Bill Toulas
·Published May 13, 2026
·Updated
Affected Software
4 affected components
Microsoft Windows=11
Microsoft Windows Server=2022
Microsoft Windows Server=2025
Microsoft Windows
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a zero-day vulnerability in Windows BitLocker that allows unauthorized access to protected drives.
2
What are the names of the vulnerabilities mentioned in the article?
The vulnerabilities are named YellowKey, which is a BitLocker bypass, and GreenPlasma, which is a privilege-escalation flaw.
3
What software products are affected by these vulnerabilities?
The vulnerabilities affect Microsoft Windows 11, Microsoft Windows Server 2022, and Microsoft Windows Server 2025.
4
What type of exploits have been released by the cybersecurity researcher?
The researcher has published proof-of-concept (PoC) exploits demonstrating the vulnerabilities.
5
What security implications are raised by these vulnerabilities?
The vulnerabilities could potentially allow attackers to bypass encryption and escalate privileges, compromising data security.