logo

Windows BitLocker 0-Day Vulnerability Exposes Encrypted Drives to Unauthorized Access

ID: e3464f2d-656d-5e7c-8da9-9aedce2402c6

STIX ID: report--e3464f2d-656d-5e7c-8da9-9aedce2402c6

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Divya

...
...

YellowKey is a publicly disclosed Windows zero-day that can bypass BitLocker by exploiting a weakness in the Windows Recovery Environment (WinRE). The attack, demonstrated against Windows 11 and recent server editions, uses specially crafted files on USB media or the EFI system partition to cause WinRE to replay NTFS transaction logs and open a shell with access to BitLocker-protected volumes; the disclosure includes public proof-of-concept materials and a related flaw called GreenPlasma. Organizations using affected platforms should assume physical-access threats, review BitLocker protector settings and WinRE exposure, and apply any vendor guidance when available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.