logo

Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation

ID: c2ec7d3c-968b-5f69-9428-574552138d4c

STIX ID: report--c2ec7d3c-968b-5f69-9428-574552138d4c

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** An anonymous researcher disclosed two new zero-days — YellowKey, a BitLocker bypass that leverages specially crafted FsTx files replayed from a USB/EFI partition to obtain a shell during WinRE boot (bypassing TPM+PIN), and GreenPlasma, an incomplete PoC for a CTFMON privilege escalation allowing arbitrary section creation in SYSTEM-writable directory objects; the report also recounts a boot manager downgrade attack (CVE-2025-48804) that enables BitLocker compromise and recommends mitigations such as enabling BitLocker PIN/preboot authentication and migrating/revoking legacy boot manager certificates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.