YellowKey Zero-Day Breaks BitLocker via USB

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Chaotic Eclipse (aka Nightmare-Eclipse) published YellowKey, a zero-day exploit that bypasses Microsoft BitLocker by copying files to a USB stick and triggering a Windows Recovery Environment reboot — granting full access to the encrypted drive without any key prompt.
- The YellowKey process requires no menus or confirmation: holding Control during the reboot drops the user directly into an elevated command line, and the exploit's files self-delete from the USB after a single use.
- YellowKey works on Windows Server 2022 and 2025 but not Windows 10; the researcher claims a TPM-and-PIN variant exists, though no proof-of-concept has been published.
- GreenPlasma, the second zero-day, is an incomplete local privilege escalation that allegedly gains system-level access by manipulating the CTFMon process to place a crafted memory section object into a Windows Object Manager location writable by SYSTEM.
- Eclipse says their disclosure reports were dismissed by Microsoft's security team, motivating public release; they stated they "could have made some insane cash selling this, but no amount of money will stand between me and my determination against Microsoft."
- BitLocker is enabled by default in Windows 11 and protects millions of machines across home, enterprise, and government; as of publication, Microsoft has issued no official response to either exploit, though the prior BlueHammer was patched and RedSun was allegedly silently patched.
Why it matters: For any organization relying on BitLocker — the default disk encryption in Windows 11 and widely deployed across enterprises and government — YellowKey means a physically stolen laptop, desktop, or server is effectively unlocked. The exploit's confirmed reach into Windows Server 2022 and 2025 turns every server room with physical access into a potential breach point until Microsoft ships a fix.
Ask SkimNews


