logo

Microsoft's worst 'Nightmare' unleashes BitLocker bypass 0-day

ID: c6a1a33e-066f-518b-ada4-661f31e31b30

STIX ID: report--c6a1a33e-066f-518b-ada4-661f31e31b30

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-06-11

Date Updated: 2026-06-12

...
...

Nightmare Eclipse released public exploit code called "GreatXML" that they claim can spawn a shell with unrestricted access to a BitLocker volume by copying "unattend.xml" and a "Recovery" directory to the recovery partition and rebooting into WinRE to trigger a Microsoft Defender Offline scan; independent testing reported reproduction issues and Microsoft says it is investigating.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.