# Microsoft Emergency Patches Three Critical Zero-Days in Windows and BitLocker


Microsoft moved quickly on Tuesday to patch three high-severity zero-day vulnerabilities that grant attackers either SYSTEM-level privileges on fully patched Windows systems or the ability to bypass BitLocker encryption on devices with physical access. The trio of flaws—GreenPlasma, MiniPlasma, and YellowKey—were disclosed last month by security researcher "Nightmare Eclipse" and represent the latest escalation in a high-profile clash between the researcher and Microsoft over vulnerability disclosure practices.


## The Threat: Three Pathways to Compromise


The three patched vulnerabilities create multiple attack surfaces on Windows systems:


GreenPlasma (CVE-2026-45586) and MiniPlasma (CVE-2020-17103) are local privilege escalation (LPE) flaws that allow attackers with basic user-level access to obtain SYSTEM permissions—the highest privilege level on Windows. GreenPlasma lives in the Collaborative Translation Framework (CTFMON), a Windows component that handles text services and input methods. MiniPlasma exists in the Cloud Files Mini Filter Driver, a storage management component. Both can be exploited entirely from the user's local system without requiring network access.


YellowKey (CVE-2026-45585) targets a different attack surface: the Windows Recovery Environment (WinRE). This is the system that boots when Windows fails to start normally or when users need to perform recovery operations. YellowKey allows attackers with physical access to compromised machines to completely bypass BitLocker full-disk encryption on Windows 11 and Windows Server 2022/2025 systems. For organizations relying on BitLocker as a primary defense against theft or data exfiltration, this represents a critical threat.


## Background and Context: Escalating Researcher vs. Microsoft


The three patches mark the latest chapter in an increasingly contentious relationship between Microsoft and the researcher operating under the pseudonym "Nightmare Eclipse." Over the past several months, this researcher has publicly released exploits for multiple Windows zero-days in apparent protest over what they characterize as inadequate coordination and transparency in Microsoft's vulnerability disclosure process.


The timeline of releases tells the story:


  • BlueHammer (CVE-2026-33825): A local privilege escalation vulnerability that is now actively exploited in real attacks
  • RedSun: An unnamed zero-day with similar LPE capabilities, also now seeing active exploitation
  • UnDefend: A particularly insidious flaw that allows standard users to block Microsoft Defender from receiving definition updates, effectively disabling the endpoint's primary defense mechanism
  • RoguePlanet: Disclosed mere hours after Microsoft released this month's patches, RoguePlanet allows attackers to spawn command prompts with SYSTEM privileges

  • Microsoft initially responded to these leaks with legal threats, but faced significant public backlash on social media platforms. The company ultimately backed down, issuing a more measured statement indicating it would work with law enforcement only in cases where researchers engage in "malicious activity causing real harm" to customers—effectively acknowledging that releasing proof-of-concept code is not itself considered inherently malicious by public standards.


    ## Technical Deep Dive


    ### GreenPlasma: Collaborative Translation Framework Escalation


    The Collaborative Translation Framework (CTFMON) is a relatively obscure Windows component that manages input methods, text services, and translation features. GreenPlasma exploits a logic flaw in how CTFMON handles certain operations. An attacker with local access can trigger a code execution path that executes with SYSTEM privileges. The vulnerability likely stems from improper input validation or insecure file operations that fail to check whether a lower-privileged process should be able to access them.


    ### MiniPlasma: Cloud Files Filter Driver Flaw


    The Cloud Files Mini Filter Driver is part of Windows' file system filter management, used to intercept and manage I/O operations on storage devices. MiniPlasma appears to exploit a similar pattern of privilege boundaries not being properly enforced. By crafting specific requests or manipulating file system state, a local attacker can escalate privileges without requiring administrative credentials.


    ### YellowKey: BitLocker's Fatal Weakness in Recovery Mode


    YellowKey is arguably the most dangerous of the three because it targets BitLocker, often the last line of defense for stolen or physically compromised devices. The Windows Recovery Environment (WinRE) is supposed to be protected, but YellowKey demonstrates a way to break out of its isolation and access the BitLocker key material. An attacker with physical access can reboot the device into recovery mode, exploit YellowKey, and decrypt the entire drive—rendering BitLocker protection worthless.


    ## Who Is at Risk?


    Enterprise organizations face the broadest exposure. All three vulnerabilities affect local attack scenarios:


  • Internal threats or compromised employee accounts can escalate to system level using GreenPlasma or MiniPlasma
  • Stolen laptops can be decrypted using YellowKey, exposing sensitive data
  • Cloud storage synchronization flaws could be chained with other exploits to create multi-stage attack chains

  • Government agencies and military institutions are particularly exposed to YellowKey, which specifically undermines secure data protection on mobile devices—a core requirement for classified information handling.


    Healthcare and financial services organizations rely heavily on BitLocker for regulatory compliance. YellowKey directly undermines their security posture.


    ## Implications: The Disclosure Debate Becomes Real


    These patches highlight a genuine tension in cybersecurity: should researchers be allowed to publicly disclose proof-of-concept code when vendors don't fix flaws quickly enough?


    Microsoft maintains this violates responsible disclosure practices. The company argues that releasing PoC code enables widespread attacks. However, Nightmare Eclipse appears to be making a different argument: that Microsoft's MSRC process is slow, opaque, and unresponsive to researchers, necessitating public pressure to force action.


    The fact that some of these vulnerabilities (BlueHammer, RedSun) are now actively exploited in real attacks validates one of Microsoft's concerns. However, it also raises the question: how long were these flaws known to Microsoft before being patched? If the vendor's internal process was already slow, public disclosure may have actually *accelerated* patches rather than delayed them.


    ## Recommendations for Defenders


    Immediate actions:


  • Apply the June 2026 Patch Tuesday updates to all Windows systems, with priority on Windows 11 and Server 2022/2025
  • Review BitLocker status on all devices—confirm encryption is enabled and that recovery keys are securely stored offline
  • Audit local administrative access: reduce the number of user accounts with local admin privileges to limit GreenPlasma/MiniPlasma impact
  • Verify that endpoint detection and response (EDR) tools are configured to alert on SYSTEM privilege escalation attempts

  • Medium-term hardening:


  • Test your monitoring for privilege escalation patterns; 54% of successful attacks go undetected
  • Disable WinRE when not needed, or implement firmware-level protections to prevent boot into recovery mode
  • Implement application whitelisting to prevent SYSTEM-level code execution from uncommon processes (CTFMON, Cloud Files drivers)
  • Enforce multi-factor authentication even for local access where possible

  • Strategic considerations:


  • Organizations should assume that sophisticated threat actors already have exploits for these vulnerabilities and may be using them before patching is complete
  • Threat intelligence teams should monitor for any mention of YellowKey, GreenPlasma, or MiniPlasma in intrusion data—their presence would indicate targeted or advanced attacks
  • Consider this a catalyst to move beyond relying on BitLocker alone; add application-level encryption for highly sensitive data

  • ---


    ## HackWire Analysis


    The Nightmare Eclipse disclosure saga reveals a critical flaw in how the security industry handles vulnerability coordination: the process is fundamentally asymmetrical. Microsoft has resources to keep exploits private for months or years, but when a researcher does the same—just in the opposite direction—we see legal threats and moral outrage.


    What's actually notable here is that Microsoft *did fix these vulnerabilities relatively quickly* after public disclosure. That suggests the process works, even if it's messy. The real question is: what took so long for Microsoft to patch GreenPlasma and MiniPlasma in the first place? If these flaws existed in production code for months before Nightmare Eclipse revealed them, then the researcher may have a legitimate grievance about MSRC's responsiveness.


    The timing also matters. YellowKey's BitLocker bypass arrives at a moment when enterprise IT is increasingly relying on encryption-at-rest as a primary control. The vulnerability isn't a subtle bug—it's a fundamental design weakness showing that physical possession plus a known exploit equals total compromise. That should shake confidence in any security strategy that treats physical devices as automatically secure if locked.


    For defenders, the real lesson isn't "panic and patch." It's that privilege escalation chains are now reliable enough to be publicly exploited. That means your monitoring has to assume every user-level compromise could become system-level within minutes. If your EDR is configured to only alert on obvious indicators, these vulnerabilities will walk right through.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)