logo

Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research

ID: ae728e88-5c38-5172-b05c-e21398c5890e

STIX ID: report--ae728e88-5c38-5172-b05c-e21398c5890e

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Pierluigi Paganini

...
...

GreatXML is a newly published zero-day exploit that abuses leftover Microsoft Defender Offline Scan configuration artifacts on the recovery partition to trick Windows Recovery Environment into executing crafted XML, yielding a SYSTEM shell and full access to BitLocker-protected volumes. The PoC requires the ability to copy an unattend.xml and a Recovery directory to the recovery partition (brief physical access or write access to the partition) and currently has no patch, making machines that have run Defender Offline Scan particularly at risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.