logo

New Windows BitLocker Zero-Day Bypasses Drive Encryption

ID: 3abca96a-9af4-58f6-87d4-45bcf1dcf736

STIX ID: report--3abca96a-9af4-58f6-87d4-45bcf1dcf736

Feed Name: Cyber Press

Threat Score
82/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: AnuPriya

...
...

**YellowKey Windows BitLocker zero-day:** A publicly disclosed proof-of-concept (PoC) named YellowKey abuses the Windows Recovery Environment to bypass BitLocker encryption on Windows 11, Server 2022, and Server 2025 without the recovery key; a companion vulnerability, GreenPlasma, can enable local privilege escalation and the two could be chained. The disclosure is validated by independent researchers, no patch is available at time of reporting, and the PoC can be delivered via specially crafted files on removable media or written to the EFI system partition, exposing unmitigated risk to systems with physical or recovery-path access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.