logo

What YellowKey and GreenPlasma zero-day exploits reveal about trusting native Windows security

ID: 6204df5e-059b-5706-aa73-8d89cec68981

STIX ID: report--6204df5e-059b-5706-aa73-8d89cec68981

Feed Name: ThreatLocker Blog

Threat Score
60/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

...
...

On May 13, 2026 a researcher published proof-of-concept exploits for two unpatched Windows zero-days—YellowKey (a BitLocker WinRE bypass requiring physical access) and GreenPlasma (a local privilege escalation via CTFMON)—affecting Windows 11 and Windows Server variants; no CVEs or patches exist yet. The report evaluates operational risk, emphasizes that YellowKey is constrained by physical access while GreenPlasma aids post-compromise escalation, and provides mitigations including restricting removable media, locking boot/firmware, enforcing BitLocker PIN, application allowlisting, process ringfencing, and least-privilege controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.