# Microsoft Emergency Patches Three Critical Zero-Days in Windows and BitLocker
Microsoft moved quickly on Tuesday to patch three high-severity zero-day vulnerabilities that grant attackers either SYSTEM-level privileges on fully patched Windows systems or the ability to bypass BitLocker encryption on devices with physical access. The trio of flaws—GreenPlasma, MiniPlasma, and YellowKey—were disclosed last month by security researcher "Nightmare Eclipse" and represent the latest escalation in a high-profile clash between the researcher and Microsoft over vulnerability disclosure practices.
## The Threat: Three Pathways to Compromise
The three patched vulnerabilities create multiple attack surfaces on Windows systems:
GreenPlasma (CVE-2026-45586) and MiniPlasma (CVE-2020-17103) are local privilege escalation (LPE) flaws that allow attackers with basic user-level access to obtain SYSTEM permissions—the highest privilege level on Windows. GreenPlasma lives in the Collaborative Translation Framework (CTFMON), a Windows component that handles text services and input methods. MiniPlasma exists in the Cloud Files Mini Filter Driver, a storage management component. Both can be exploited entirely from the user's local system without requiring network access.
YellowKey (CVE-2026-45585) targets a different attack surface: the Windows Recovery Environment (WinRE). This is the system that boots when Windows fails to start normally or when users need to perform recovery operations. YellowKey allows attackers with physical access to compromised machines to completely bypass BitLocker full-disk encryption on Windows 11 and Windows Server 2022/2025 systems. For organizations relying on BitLocker as a primary defense against theft or data exfiltration, this represents a critical threat.
## Background and Context: Escalating Researcher vs. Microsoft
The three patches mark the latest chapter in an increasingly contentious relationship between Microsoft and the researcher operating under the pseudonym "Nightmare Eclipse." Over the past several months, this researcher has publicly released exploits for multiple Windows zero-days in apparent protest over what they characterize as inadequate coordination and transparency in Microsoft's vulnerability disclosure process.
The timeline of releases tells the story:
Microsoft initially responded to these leaks with legal threats, but faced significant public backlash on social media platforms. The company ultimately backed down, issuing a more measured statement indicating it would work with law enforcement only in cases where researchers engage in "malicious activity causing real harm" to customers—effectively acknowledging that releasing proof-of-concept code is not itself considered inherently malicious by public standards.
## Technical Deep Dive
### GreenPlasma: Collaborative Translation Framework Escalation
The Collaborative Translation Framework (CTFMON) is a relatively obscure Windows component that manages input methods, text services, and translation features. GreenPlasma exploits a logic flaw in how CTFMON handles certain operations. An attacker with local access can trigger a code execution path that executes with SYSTEM privileges. The vulnerability likely stems from improper input validation or insecure file operations that fail to check whether a lower-privileged process should be able to access them.
### MiniPlasma: Cloud Files Filter Driver Flaw
The Cloud Files Mini Filter Driver is part of Windows' file system filter management, used to intercept and manage I/O operations on storage devices. MiniPlasma appears to exploit a similar pattern of privilege boundaries not being properly enforced. By crafting specific requests or manipulating file system state, a local attacker can escalate privileges without requiring administrative credentials.
### YellowKey: BitLocker's Fatal Weakness in Recovery Mode
YellowKey is arguably the most dangerous of the three because it targets BitLocker, often the last line of defense for stolen or physically compromised devices. The Windows Recovery Environment (WinRE) is supposed to be protected, but YellowKey demonstrates a way to break out of its isolation and access the BitLocker key material. An attacker with physical access can reboot the device into recovery mode, exploit YellowKey, and decrypt the entire drive—rendering BitLocker protection worthless.
## Who Is at Risk?
Enterprise organizations face the broadest exposure. All three vulnerabilities affect local attack scenarios:
Government agencies and military institutions are particularly exposed to YellowKey, which specifically undermines secure data protection on mobile devices—a core requirement for classified information handling.
Healthcare and financial services organizations rely heavily on BitLocker for regulatory compliance. YellowKey directly undermines their security posture.
## Implications: The Disclosure Debate Becomes Real
These patches highlight a genuine tension in cybersecurity: should researchers be allowed to publicly disclose proof-of-concept code when vendors don't fix flaws quickly enough?
Microsoft maintains this violates responsible disclosure practices. The company argues that releasing PoC code enables widespread attacks. However, Nightmare Eclipse appears to be making a different argument: that Microsoft's MSRC process is slow, opaque, and unresponsive to researchers, necessitating public pressure to force action.
The fact that some of these vulnerabilities (BlueHammer, RedSun) are now actively exploited in real attacks validates one of Microsoft's concerns. However, it also raises the question: how long were these flaws known to Microsoft before being patched? If the vendor's internal process was already slow, public disclosure may have actually *accelerated* patches rather than delayed them.
## Recommendations for Defenders
Immediate actions:
Medium-term hardening:
Strategic considerations:
---
## HackWire Analysis
The Nightmare Eclipse disclosure saga reveals a critical flaw in how the security industry handles vulnerability coordination: the process is fundamentally asymmetrical. Microsoft has resources to keep exploits private for months or years, but when a researcher does the same—just in the opposite direction—we see legal threats and moral outrage.
What's actually notable here is that Microsoft *did fix these vulnerabilities relatively quickly* after public disclosure. That suggests the process works, even if it's messy. The real question is: what took so long for Microsoft to patch GreenPlasma and MiniPlasma in the first place? If these flaws existed in production code for months before Nightmare Eclipse revealed them, then the researcher may have a legitimate grievance about MSRC's responsiveness.
The timing also matters. YellowKey's BitLocker bypass arrives at a moment when enterprise IT is increasingly relying on encryption-at-rest as a primary control. The vulnerability isn't a subtle bug—it's a fundamental design weakness showing that physical possession plus a known exploit equals total compromise. That should shake confidence in any security strategy that treats physical devices as automatically secure if locked.
For defenders, the real lesson isn't "panic and patch." It's that privilege escalation chains are now reliable enough to be publicly exploited. That means your monitoring has to assume every user-level compromise could become system-level within minutes. If your EDR is configured to only alert on obvious indicators, these vulnerabilities will walk right through.
— *HackWire Editorial*
---
## Related Coverage