logo

Windows BitLocker zero-day gives access to protected drives, PoC released

ID: 3dfae3a8-8dd5-5e8d-a059-beb2419dbd73

STIX ID: report--3dfae3a8-8dd5-5e8d-a059-beb2419dbd73

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Bill Toulas

...
...

A researcher publicly released PoC exploits for two unpatched Windows vulnerabilities: YellowKey, a BitLocker bypass that leverages specially crafted FsTx files and WinRE behavior to spawn a shell with access to encrypted volumes on Windows 11 and Windows Server 2022/2025 (noted to affect TPM-only BitLocker configurations), and GreenPlasma, an incomplete but potentially chainable privilege-escalation issue capable of yielding SYSTEM privileges; independent researchers confirmed YellowKey and the researcher has signaled intent to continue leaking exploits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.