logo

Two Unpatched Windows Exploits Target BitLocker, SYSTEM Access

ID: 301b68b3-224d-51d0-b51c-d556a85dace6

STIX ID: report--301b68b3-224d-51d0-b51c-d556a85dace6

Feed Name: TechRepublic Security

Threat Score
75/100

Date Published: 2026-05-15

Date Updated: 2026-05-16

Author: Joseph Ofonagoro

...
...

Microsoft’s May Patch Tuesday did not address two serious Windows vulnerabilities disclosed by researcher Chaotic Eclipse: YellowKey can bypass BitLocker by inserting a specially crafted USB while in the Windows Recovery Environment to gain a privileged shell and access decrypted volumes, and GreenPlasma is a local privilege escalation via CTFMON.exe shared-memory misuse that can allow a standard user to achieve SYSTEM privileges; PoC details were published, fixes are not yet available, and mitigations cited include enabling a BootLoader PIN and standard endpoint protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.