Security researcher Chaotic Eclipse, also known online as Nightmare-Eclipse, has disclosed two new Windows zero-day exploits named YellowKey and GreenPlasma. The vulnerabilities target BitLocker encryption and Windows privilege handling respectively, with YellowKey attracting particular attention because it reportedly allows access to BitLocker-protected drives under certain conditions. According to the published technical details, YellowKey works by placing specially prepared files onto a USB storage device with write access to the “System Volume Information” directory. After rebooting into the Windows Recovery Environment using a specific keyboard sequence, affected systems reportedly launch directly into an elevated command prompt with full access to the encrypted drive contents without requesting BitLocker recovery credentials. Testing referenced in the disclosure suggests the exploit affects Windows 11 as well as Windows Server 2022 and 2025 systems. Windows 10 reportedly does not appear vulnerable. The attack still requires physical access to the target machine, but because BitLocker is widely enabled by default on modern Windows 11 systems, the implications could be significant for laptops, workstations, and enterprise deployments.
Current information indicates the exploit does not allow encrypted drives to simply be removed and opened on unrelated hardware, as BitLocker keys remain associated with the original system TPM. Instead, the attack targets the original device directly through the recovery environment.
The researcher additionally claims that TPM-and-PIN BitLocker configurations may also be vulnerable through another unpublished variation of the exploit. One aspect generating additional discussion is the exploit’s apparent cleanup behavior, with reports indicating some files disappear from the USB device after successful execution.
Alongside YellowKey, Chaotic Eclipse also published information on a second vulnerability named GreenPlasma. This exploit allegedly enables local privilege escalation to SYSTEM-level access by manipulating the CTFMon process and crafted memory section objects inside the Windows Object Manager subsystem.
If accurate, GreenPlasma would allow attackers or malicious software to bypass normal access restrictions and gain complete control over affected systems. Such vulnerabilities are particularly concerning in shared workstation or server environments where ordinary users could potentially escalate privileges beyond intended limits.
The disclosures continue a recent series of Windows security issues published by the same researcher, including earlier exploits named BlueHammer and RedSun. Those vulnerabilities reportedly resulted in administrator-level access through Windows Defender-related behavior and were later addressed through Windows updates.
As of publication, Microsoft has not released an official public response regarding YellowKey or GreenPlasma, and no official mitigations or security advisories have yet been posted.
Source: Tom’s Hardware
ASUS ProArt RTX 5090 OC Features Compact 2.5-Slot Design
NVIDIA Bundles 007 First Light With GeForce RTX 50 Series Hardware
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
