Skip to content
A vulnerability has been discovered that allows access to Microsoft BitLocker-protected ...

A vulnerability has been discovered that allows access to Microsoft BitLocker-protected ...

Gigazine May 14, 2026

A zero-day vulnerability called ' YellowKey ,' which could potentially bypass Microsoft's BitLocker-encrypted drives, has been disclosed by security researcher Nightmare-Eclipse. Alongside this, another zero-day vulnerability, ' GreenPlasma ,' which could lead to escalation to SYSTEM privileges, has also been revealed. GitHub - Nightmare-Eclipse/YellowKey: YellowKey Bitlocker Bypass Vulnerability · GitHub

The affected versions are Windows 11, Windows Server 2022, and Windows Server 2025, but Windows 10 is not affected. Nightmare-Eclipse claims that the component related to this issue exists in the Windows Recovery Environment and behaves differently from the component of the same name in a normal Windows environment, making it 'feel like a backdoor.' Technology media outlet Tom's Hardware has confirmed that YellowKey works in-house, reporting that it was able to access BitLocker-protected drives without requiring any key input. They also point out that the behavior is unusual, going beyond a simple vulnerability, including the fact that related files disappear from the USB drive after the exploit is executed. Another zero-day vulnerability, 'GreenPlasma,' is a privilege escalation vulnerability targeting CTFMON.exe, a Windows text input-related process. According to the security news site Cybernews, the published proof of concept is an incomplete version lacking the final element to obtain a complete SYSTEM shell, but it suggests that understanding the mechanism could lead to full privilege escalation. Tom's Hardware points out that the impact of this newly discovered vulnerability is significant because BitLocker is widely used in Windows 11 environments. While BitLocker's key is stored in the TPM , meaning the drive cannot be immediately opened by simply transferring it to another PC, they explain that it could pose a serious risk if the device itself is stolen. Nightmare-Eclipse has indicated that he may continue to disclose vulnerabilities due to his conflict with Microsoft, and has warned that 'the Patch Tuesday will be a big surprise.'

Another zero-day vulnerability, 'GreenPlasma,' is a privilege escalation vulnerability targeting CTFMON.exe, a Windows text input-related process. According to the security news site Cybernews, the published proof of concept is an incomplete version lacking the final element to obtain a complete SYSTEM shell, but it suggests that understanding the mechanism could lead to full privilege escalation. Tom's Hardware points out that the impact of this newly discovered vulnerability is significant because BitLocker is widely used in Windows 11 environments. While BitLocker's key is stored in the TPM , meaning the drive cannot be immediately opened by simply transferring it to another PC, they explain that it could pose a serious risk if the device itself is stolen. Nightmare-Eclipse has indicated that he may continue to disclose vulnerabilities due to his conflict with Microsoft, and has warned that 'the Patch Tuesday will be a big surprise.'

May 14, 2026 12:05:00 in Software , Security , Posted by log1i_yk

Extracted Entities

Attack Types (1)

Platforms (1)

Vulnerabilities (2)