USB stick exploits Windows BitLocker in new zero-day

Critical security flaw in Windows BitLocker could expose sensitive AI data on physical hardware.
30-Second TL;DR
What Changed
YellowKey proof-of-concept demonstrates BitLocker bypass
Why It Matters
This vulnerability could force enterprises to re-evaluate physical security protocols for devices containing sensitive AI training data or proprietary models.
What To Do Next
Audit your fleet of Windows devices and disable unauthorized USB boot capabilities in BIOS/UEFI settings.
Key Points
- •YellowKey proof-of-concept demonstrates BitLocker bypass
- •Vulnerability relies on physical access via USB interface
- •Security researchers warn of potential data exposure risks
Deep Insight
Background and context from public sources — not the original article. 11 sources cited.
Enhanced Key Takeaways
- •The YellowKey exploit specifically targets Windows 11 and Windows Server 2022/2025, with Windows 10 reportedly remaining unaffected by this particular bypass.
- •The researcher, known as Nightmare-Eclipse (or Chaotic Eclipse), suggests that the vulnerability might be an intentional backdoor, citing that the exploitable component exists only within the Windows Recovery Environment (WinRE) image with the bypass functionality, despite a similarly named component existing in normal Windows installations without it.
- •The bypass primarily affects BitLocker configurations operating in TPM-only mode, which is the default setting for many consumer devices, allowing automatic drive unlocking without user interaction.
- •The exploit involves copying a specially crafted 'FsTx' folder to a USB stick (or directly to the EFI partition), then initiating a reboot into WinRE while holding the CTRL key, which subsequently opens a command prompt with unrestricted access to the encrypted volume.
- •Alongside YellowKey, the same researcher also released a secondary proof-of-concept called GreenPlasma, which is described as a local privilege escalation vulnerability targeting the CTFMON subsystem to achieve SYSTEM-level access, though the full escalation code was not publicly released.
Technical Deep Dive
- Affected Operating Systems: Windows 11, Windows Server 2022, and Windows Server 2025 are vulnerable; Windows 10 is not affected.
- Exploit Mechanism: The YellowKey exploit leverages NTFS transactions in conjunction with specific components within the Windows Recovery Environment (WinRE) image.
- Vulnerable Component: A particular component within the WinRE image contains the functionality that triggers the bypass, even though a component with the exact same name exists in normal Windows installations without this specific vulnerability.
- Triggering the Exploit: An attacker must copy an 'FsTx' folder to a specific path within the
System Volume Informationdirectory on a USB stick (or alternatively, to the EFI partition of the target drive). - Execution Steps: The compromised USB stick is inserted, the machine is rebooted into the Windows Recovery Environment (WinRE) by holding Shift and clicking Restart, and then the CTRL key is held down during the reboot process.
- Outcome: If the timing is correct, a command prompt opens, granting unrestricted access to the BitLocker-encrypted volume, which can then be mounted using
diskpartto access its contents. - BitLocker Configuration: The exploit primarily targets BitLocker drives configured in TPM-only mode, which typically unlock automatically without requiring a pre-boot PIN. The researcher claims a version also works against TPM+PIN but has not released it.
- Researcher's Stance: The researcher, Nightmare-Eclipse, has publicly stated a belief that the vulnerability's nature suggests it could be an intentional backdoor.
- Associated Exploit: A separate local privilege escalation exploit named GreenPlasma, targeting the CTFMON subsystem for SYSTEM access, was also disclosed by the same researcher.
Future ImplicationsAI analysis grounded in cited sources
Timeline
- 2007-01Microsoft introduces BitLocker full-disk encryption with Windows Vista.
- 2022-05Microsoft addresses several BitLocker-related vulnerabilities, including CVE-2022-29127 and CVE-2022-22048, through various updates.
- 2025-07Microsoft patches CVE-2025-48804, a critical WinRE vulnerability, which later enables the 'BitUnlocker' downgrade attack due to unrevoked certificates.
- 2025-11Researcher Guillaume Quéré demonstrates a physical attack bypassing BitLocker PIN authentication by capturing the Volume Master Key (VMK) from the TPM via logic analyzer.
- 2026-05-12Researcher 'Nightmare-Eclipse' (Chaotic Eclipse) publicly releases the YellowKey proof-of-concept for BitLocker bypass and GreenPlasma for privilege escalation.
- 2026-05-13Security researchers confirm YellowKey's functionality; Microsoft has not yet issued a public acknowledgment or patch for this specific vulnerability.
Sources (11)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
Weekly AI Recap
Read this week's curated digest of top AI events →
AI-curated news aggregator. All content rights belong to original publishers.
Original source: iTNews Australia ↗
This is a summary, not the original. Read the source, or get the weekly briefing.
The weekly digest
One email a week. Unsubscribe anytime.