logo

New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files

ID: 73cbb81a-a795-5318-bcc4-6bd909ec590c

STIX ID: report--73cbb81a-a795-5318-bcc4-6bd909ec590c

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-06-11

Date Updated: 2026-06-12

Author: [email protected] (The Hacker News)

...
...

A new BitLocker bypass named **GreatXML** was published by researcher Chaotic Eclipse; the exploit uses crafted unattended XML files placed on the recovery partition and booting into the Windows Recovery Environment (WinRE) — particularly in a Windows Defender Offline Scan state — to spawn a shell with unrestricted access to a BitLocker-protected volume. The disclosure follows other recent researcher-released exploits (including YellowKey/CVE-2026-45585) and a separate Microsoft Defender zero-day (RoguePlanet).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.