Skip to content
GreatXML exploit enables BitLocker bypass via recovery partition manipulation

GreatXML exploit enables BitLocker bypass via recovery partition manipulation

Feeds.4Sysops IT News June 11, 2026

A new security vulnerability known as GreatXML allows attackers to bypass BitLocker drive encryption by manipulating files within the Windows recovery partition. The exploit involves placing specific XML files, including an unattended setup file and a recovery configuration file, into the root of the recovery partition. Systems that have previously initiated a Microsoft Defender offline scan are reportedly vulnerable to this attack by default. Source

Extracted Entities

Attack Types (1)

Platforms (1)

Vulnerabilities (1)