logo

Zero-day exploit completely defeats default Windows 11 BitLocker protections

ID: 850e68ca-e668-56e0-b738-607fbe8a157f

STIX ID: report--850e68ca-e668-56e0-b738-607fbe8a157f

Feed Name: Security - Ars Technica

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-22

Author: Dan Goodin

...
...

YellowKey is a published zero-day exploit that enables an attacker with physical access to a Windows 11 system to bypass BitLocker full-disk encryption within seconds by copying a custom FsTx folder to a USB drive and entering Windows Recovery; the exploit appears to leverage Transactional NTFS (fstx.dll) behavior and has been independently confirmed by multiple researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.