logo

GreatXML Zero-Day Enables BitLocker Bypass Through Windows Defender Offline Scan

ID: bf658c89-da34-5492-889d-01ffadf2280b

STIX ID: report--bf658c89-da34-5492-889d-01ffadf2280b

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Divya

...
...

A newly disclosed zero-day named “GreatXML” permits a BitLocker bypass by placing a crafted unattend.xml and modified Recovery directory on the recovery partition and forcing boot into WinRE (e.g., Shift+Restart). The researcher’s PoC claims low complexity and persistence on systems that have run Windows Defender Offline Scan, allowing an attacker with physical access to spawn a privileged shell and access encrypted volumes. There is no CVE or vendor advisory at time of writing; recommended mitigations include restricting physical access, auditing or disabling WinRE use, and reviewing Defender Offline Scan deployment policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.