logo

GreatXML BitLocker Bypass: Public PoC Exploit Disclosed

ID: a529618c-1aaa-5a7d-af1e-2c4b5043c4d2

STIX ID: report--a529618c-1aaa-5a7d-af1e-2c4b5043c4d2

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Do Son

...
...

A researcher published a public proof-of-concept for the “GreatXML” exploit that manipulates Windows Defender Offline Scan / WinRE to bypass BitLocker and spawn an unrestricted administrative shell; the attack requires placing an unattend.xml and a Recovery directory on the recovery partition and booting into WinRE (or a system in the offline-scan state), so it poses a serious local/physical risk to affected systems—proof-of-concept code is available on GitHub and Microsoft is expected to issue a patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.