# GreatXML: New BitLocker Bypass Exposes Critical Windows Recovery Partition Vulnerability


Security researcher releases second BitLocker bypass in days, highlighting systemic vulnerabilities in Windows encryption defenses


A newly disclosed exploit dubbed GreatXML allows attackers to completely bypass Windows BitLocker encryption by manipulating XML files on the recovery partition, granting unrestricted access to encrypted volumes. The vulnerability, released by security researcher Chaotic Eclipse on June 11, 2026, represents the second BitLocker bypass from the same researcher in as many weeks and underscores a troubling pattern in Windows security defenses.


## The Threat


GreatXML exploits a critical design flaw in how Windows Recovery Environment (WinRE) handles XML configuration files, particularly those found in the recovery partition. According to Chaotic Eclipse, the exploit is straightforward to execute but devastating in its impact:


Attack requirements:

  • Physical or logical access to the device's recovery partition
  • Ability to place two XML files in specific locations
  • Access to Windows Recovery Environment via Shift+Restart
  • No authentication credentials needed

  • Once successfully executed, the exploit grants the attacker a shell with unrestricted access to the BitLocker-encrypted volume—completely circumventing the encryption that was supposed to protect the data.


    ## How GreatXML Works: Technical Details


    The exploit leverages two XML configuration files placed strategically on the recovery partition:


    1. unattend.xml (placed at recovery partition root)

    2. Recovery/WindowsRE/ReAgent.xml (placed in the recovery directory)


    The attack flow is remarkably simple but effective:


    Step-by-step exploitation:

    1. Attacker gains access to the recovery partition (through physical access, USB boot, or other means)

    2. Copies the malicious XML files to the specified locations

    3. Initiates reboot to Windows Recovery Environment (WinRE) by holding Shift while clicking Restart

    4. Follows through the recovery process without requiring BitLocker recovery keys

    5. Receives a shell with full access to the encrypted volume


    Chaotic Eclipse noted that users who have ever initiated a Windows Defender Offline Scan are automatically vulnerable. The offline scan feature creates conditions that make the exploitation path viable. However, the researcher indicated that other attack vectors likely exist to trigger WinRE without prior offline scan usage.


    "This was an accidental discovery, it took a total of 4 hours to find this," the researcher posted on Blogger, suggesting the vulnerability stems from fundamental design oversights rather than obscure edge cases.


    ## Context: A Week of BitLocker Breaches


    GreatXML arrives in the context of an unprecedented streak of BitLocker and Windows security disclosures:


    | Vulnerability | Researcher | Date | Impact |

    |---|---|---|---|

    | RoguePlanet | Chaotic Eclipse | June 10, 2026 | Microsoft Defender LPE to SYSTEM |

    | GreatXML | Chaotic Eclipse | June 11, 2026 | BitLocker bypass via recovery partition |

    | YellowKey | Chaotic Eclipse | Earlier June 2026 | BitLocker bypass (CVE-2026-45585) |


    Microsoft released patches for YellowKey as part of Patch Tuesday, but the rapid succession of disclosures suggests deeper architectural problems in Windows security design. The fact that all three come from the same researcher raises questions about whether Chaotic Eclipse has uncovered a systematic weakness in how Windows handles encryption, privileged operations, and recovery mechanisms.


    ## Implications for Organizations


    ### Immediate Risk


    Organizations using BitLocker for full-disk encryption should recognize a critical limitation: physical or local access to the device can now bypass the encryption entirely. This fundamentally changes the threat model for:


  • Remote workers with company laptops
  • Devices in transit or in public spaces
  • Corporate environments where devices might be stolen or accessed by malicious insiders
  • Disaster recovery scenarios where recovery partitions must be accessible

  • ### Supply Chain and Manufacturing


    Organizations that image or prepare systems before deployment are at particular risk. If attackers compromise the imaging process to inject malicious XML files before recovery partitions are finalized, they could establish a persistent backdoor on every deployed device.


    ### Compliance Impact


    Regulations like GDPR, HIPAA, PCI-DSS, and SOC 2 often mandate full-disk encryption as a control to protect sensitive data. A complete BitLocker bypass undermines the compliance posture of affected organizations, potentially creating breach notification obligations even if the data was encrypted.


    ## The Bigger Picture: Recovery Partition Neglect


    The recovery partition—that small, often-invisible portion of modern Windows devices—has historically received minimal security attention. It's treated as a maintenance tool rather than a security boundary. Yet GreatXML and the previous YellowKey vulnerability demonstrate that the recovery partition is a prime attack surface for bypassing security controls.


    Recovery partitions are rarely monitored, rarely audited, and often excluded from standard endpoint protection scans. For years, security practitioners have focused on securing the main Windows partition while leaving the recovery environment relatively unprotected—an assumption that these new exploits have rendered dangerously obsolete.


    ## Recommendations for Defenders


    ### Immediate Actions (Critical)


  • Assess exposure: Determine which systems have initiated Windows Defender Offline Scans, as these are automatically vulnerable
  • Disable WinRE where not required: If recovery environment access is not necessary for organizational operations, disable it via reagentc /disable
  • Apply available patches: Install Microsoft's Patch Tuesday updates addressing YellowKey and other BitLocker issues
  • Require TPM + PIN: Enforce BitLocker PIN protection in addition to TPM, requiring authentication to access encrypted volumes

  • ### Medium-Term Defenses


  • Monitor recovery partitions: Implement file integrity monitoring on recovery partition contents
  • Restrict recovery access: Configure BIOS/UEFI settings to prevent unauthorized recovery environment access
  • Full-disk encryption + additional layers: Layer BitLocker with hardware security modules (HSMs) or additional encryption at the application level for high-value data
  • Secure boot enforcement: Ensure Secure Boot is enabled and that recovery environments cannot be bypassed

  • ### Strategic Considerations


  • Evaluate alternatives: For extremely high-security environments, consider alternative disk encryption solutions or additional layers beyond BitLocker
  • Zero-trust recovery: Treat the recovery environment as untrusted; require authentication and authorization even for recovery operations
  • Incident response drills: Update incident response procedures to account for potential BitLocker bypass attacks during physical compromise scenarios

  • ## HackWire Analysis


    The rapid succession of BitLocker and Windows security vulnerabilities in early June 2026 signals a troubling pattern: Windows' foundational security architecture may have systematic design flaws that can't be patched away incrementally.


    Three separate exploits from the same researcher in days suggests these aren't isolated bugs—they're symptoms of how Windows prioritizes backward compatibility and usability over defense-in-depth. The recovery partition, in particular, has been treated as "outside the security boundary" for so long that basic controls (file verification, signed XML validation, access restrictions) are absent.


    What's most concerning is the timing and accessibility. YellowKey requires CVE patches. RoguePlanet requires specific Defender versions. But GreatXML? It requires nothing more than the ability to write files to a partition and reboot—a threat model that encompasses physical theft, supply-chain compromise, malicious IT staff, and compromised imaging tools.


    For organizations that have relied on BitLocker as their primary encryption defense, this vulnerability class demands immediate reassessment. BitLocker remains valuable, but treating it as a standalone security control is no longer defensible. Recovery partitions must be treated as security-critical assets worthy of the same monitoring, access controls, and integrity verification as the main operating system.


    The broader lesson: Windows security is undergoing stress testing right now, and the cracks are showing. Microsoft's patch cycle will eventually address these specific vulnerabilities, but the fundamental design principles that allowed these bypasses to exist in the first place will likely persist—creating a pattern of similar disclosures in the months ahead.


    — *HackWire Editorial*


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)