Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
ID: bd14691e-7a30-5b7e-8538-2ab60acd4a07
STIX ID: report--bd14691e-7a30-5b7e-8538-2ab60acd4a07
Feed Name: securityonline.info
A researcher calling themselves Chaotic Eclipse (aka Nightmare-Eclipse) publicly released PoC exploit code for two Windows zero-day vulnerabilities on GitHub: YellowKey, which enables a complete BitLocker bypass via a WinRE component allowing shell access from a USB during reboot, and GreenPlasma, which abuses the CTFMON service to create arbitrary memory section objects and escalate to SYSTEM. Both exploits are reported to work on Windows 11 and multiple Windows Server versions; the public availability of the PoC increases risk to organizations and the researcher framed the release as retaliation against Microsoft with warnings of further disclosures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
