New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
ID: 73cbb81a-a795-5318-bcc4-6bd909ec590c
STIX ID: report--73cbb81a-a795-5318-bcc4-6bd909ec590c
Feed Name: The Hacker News
A new BitLocker bypass named **GreatXML** was published by researcher Chaotic Eclipse; the exploit uses crafted unattended XML files placed on the recovery partition and booting into the Windows Recovery Environment (WinRE) — particularly in a Windows Defender Offline Scan state — to spawn a shell with unrestricted access to a BitLocker-protected volume. The disclosure follows other recent researcher-released exploits (including YellowKey/CVE-2026-45585) and a separate Microsoft Defender zero-day (RoguePlanet).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
