• News/
  • bleepingcomputer-20260513163749

Windows BitLocker zero-day gives access to protected drives, PoC released

BleepingComputer
·
Bill Toulas
·
Published May 13, 2026
·
Updated

A cybersecurity researcher has published proof-of-concept (PoC) exploits for two unpatched Microsoft Windows vulnerabilities named YellowKey and GreenPlasma, which are a BitLocker bypass and a privilege-escalation flaw. Known as Chaotic Eclipse or Nightmare Eclipse, the researcher describes the BitLocker bypass issue as functioning like a backdoor because the vulnerable component is present only in the Windows Recovery Environment (WinRE), which is used to repair boot-related issues in Windows. The latest exploits follow the researcher's previous disclosure of the BlueHammer (CVE-2026-33825) and RedSun (no identifier) local privilege escalation (LPE)  as zero-day flaws, both of which began to be exploited in the wild shortly after being publicly disclosed. As in previous cases, the researcher stated that the decision to publicly disclose the YellowKey and GreenPlasma vulnerabilities, along with guidance on how to leverage them, was driven by dissatisfaction with Microsoft’s handling of bug reports. Chaotic Eclipse, or Nightmare-Eclipse on GitHub, said that they will keep leaking exploits for undocumented Windows vulnerabilities, even promising “a big surprise” for the next Patch Tuesday. The researcher says that YellowKey is a BitLocker bypass that affects Windows 11 and Windows Server 2022/2025. It involves placing specially crafted ‘FsTx’ files on a USB drive or EFI partition, rebooting into WinRE, and triggering a shell by holding down the CTRL key. Additionally, the BitL...

Read full article

Affected Software

4 affected components
Microsoft Windows=11
Microsoft Windows Server=2022
Microsoft Windows Server=2025
Microsoft Windows
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day vulnerability in Windows BitLocker that allows unauthorized access to protected drives.

2

What are the names of the vulnerabilities mentioned in the article?

The vulnerabilities are named YellowKey, which is a BitLocker bypass, and GreenPlasma, which is a privilege-escalation flaw.

3

What software products are affected by these vulnerabilities?

The vulnerabilities affect Microsoft Windows 11, Microsoft Windows Server 2022, and Microsoft Windows Server 2025.

4

What type of exploits have been released by the cybersecurity researcher?

The researcher has published proof-of-concept (PoC) exploits demonstrating the vulnerabilities.

5

What security implications are raised by these vulnerabilities?

The vulnerabilities could potentially allow attackers to bypass encryption and escalate privileges, compromising data security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203