# Windows BitLocker Zero-Day Allows Full Disk Decryption; Researcher Promises More Exploits on Patch Tuesday
A cybersecurity researcher operating under the pseudonym Chaotic Eclipse has released functional proof-of-concept exploits for two critical unpatched Microsoft Windows vulnerabilities—codenamed YellowKey and GreenPlasma—that enable attackers to bypass BitLocker encryption and escalate privileges on affected systems. The disclosure marks an escalation in the researcher's campaign of public vulnerability releases and raises serious questions about the vulnerability disclosure ecosystem and Microsoft's patch velocity.
## The Threat: Full BitLocker Bypass
YellowKey is a BitLocker bypass, not a mere workaround. The vulnerability affects Windows 11 and Windows Server 2022/2025 and operates by exploiting the Windows Recovery Environment (WinRE)—the repair partition used when systems fail to boot normally.
The attack sequence is straightforward:
According to vulnerability analyst Will Dormann at Tharros Labs, the exploit abuses NTFS transaction logs that WinRE processes during startup. By placing malicious FsTx directories in \System Volume Information\, the exploit causes WinRE to delete the legitimate winpeshl.ini configuration file. When the recovery environment loads, instead of launching the genuine Windows Recovery interface, it drops the attacker into a command prompt—with the encrypted disk already decrypted and accessible.
"The disk is still unlocked," Dormann confirmed after reproducing the exploit.
## Background and Context: A Cascade of Disclosures
YellowKey and GreenPlasma are not Chaotic Eclipse's first public vulnerability disclosures. The researcher previously released exploits for:
Both vulnerabilities entered active exploitation in the wild shortly after public disclosure, demonstrating that publishing working exploits carries real-world consequences.
The researcher has explicitly stated that dissatisfaction with Microsoft's vulnerability handling prompted these disclosures. In a statement, Chaotic Eclipse said they will "keep leaking exploits for undocumented Windows vulnerabilities" and promised "a big surprise" for the next Patch Tuesday—a veiled threat of additional zero-day releases timed to maximum visibility.
This disclosure pattern reflects a broader frustration within the security research community about Microsoft's patch timelines, communication with researchers, and prioritization of urgent flaws. However, public disclosure of working exploits remains controversial: it accelerates defender response but also enables opportunistic attackers with no defensive capability.
## Technical Details: Why BitLocker Fails Here
BitLocker is designed to protect data at rest through full-disk encryption. However, the protection model assumes that the boot process itself is trustworthy. YellowKey exploits a gap in that assumption.
The core issue: The Windows Recovery Environment runs before BitLocker enforcement is fully initialized. It operates at a privileged level to repair system files, and it trusts certain boot-time components without full cryptographic verification.
By placing transaction files in locations that WinRE scans during startup, an attacker can manipulate which programs execute during recovery mode. Once WinRE launches without the legitimate shell configuration, the next prompt the user sees is a raw command interpreter—with full disk access already granted.
### Mitigation Limitations
Independent security researcher Kevin Beaumont confirmed the exploit and recommended using BitLocker PIN + BIOS password as a mitigation. However, Chaotic Eclipse pushed back, stating that the vulnerability remains exploitable even with:
The researcher claims the PIN variant exploit exists but will not release it publicly, acknowledging that "what's out there is already bad enough."
By default, TPM-only BitLocker configurations automatically unlock drives without user intervention—a convenience feature that inadvertently creates an attack surface. Defenders relying on TPM alone have no additional protection against YellowKey.
## Implications for Enterprise and Government
This vulnerability directly threatens:
| Affected Systems | Impact |
|---|---|
| Windows 11 endpoints | Full encryption bypass if attacker has physical access or can inject USB/EFI |
| Windows Server 2022/2025 | Server-side encryption protection nullified |
| Sensitive data repositories | Unencrypted access to protected information |
| Classified or regulated environments | Potential breach of data sovereignty and compliance requirements |
Physical or local access is required—an attacker cannot remotely trigger YellowKey. However, physical access is often underestimated as a threat vector:
Organizations that rely on BitLocker as their primary defense against physical disk theft now face a significant gap.
## GreenPlasma: The Second Vulnerability
Details on the GreenPlasma privilege escalation flaw are limited in current reporting, but it complements YellowKey by providing local elevation paths. Together, the two vulnerabilities form a more complete attack chain: YellowKey gains initial disk access, while GreenPlasma escalates privileges within the unlocked system.
## What Microsoft Must Do
Microsoft has not publicly acknowledged YellowKey or provided a timeline for patches. The company's MSRC (Microsoft Security Response Center) has faced repeated criticism for slow response to critical vulnerabilities, particularly those affecting encryption and system integrity.
Immediate actions should include:
---
## HackWire Analysis
The vulnerability disclosure ecosystem is fracturing. Chaotic Eclipse's escalating campaign—from BlueHammer to RedSun to YellowKey—reflects a researcher who has concluded that responsible disclosure to Microsoft produces unacceptable delays. By releasing working exploits, they've chosen to shift the cost of inaction from themselves to defenders everywhere.
This is not unique. We've seen this pattern before: researchers frustrated by slow patches turning to public disclosure as leverage. The difference here is scale and timing. YellowKey is not an edge-case flaw; it's a fundamental bypass of Windows' primary encryption defense. And it's being released before patches exist.
The real story is not the technical elegance of the exploit—it's that BitLocker's threat model assumed WinRE was trustworthy. That assumption is broken. Every organization depending on BitLocker for disk-at-rest protection must now assume that an attacker with physical access can read encrypted data. PIN and TPM provide no additional defense against YellowKey.
For enterprises, the immediate question is existential: If BitLocker can be bypassed, what encryption layer actually protects sensitive data at rest? The answer, uncomfortably, is "nothing built into Windows." Organizations handling high-value intellectual property, patient data, or classified information may need to layer additional encryption above the disk level—a significant operational burden that should never have been necessary.
Chaotic Eclipse has promised further releases before Patch Tuesday. Expect more FireEye-style escalation: researchers and vendors in a race where disclosure velocity is the only leverage remaining.
— HackWire Editorial
---
## Recommendations for Organizations
Immediate steps:
1. Disable WinRE if not actively needed — reduce the attack surface if your deployment model allows it
2. Require BIOS passwords on all systems handling sensitive data — raise the cost of physical exploitation
3. Monitor for USB device connections on high-value endpoints — YellowKey requires local storage injection
4. Audit BitLocker configurations — identify systems relying on TPM-only unlock and reassess threat models
5. Prepare alternative encryption strategies — assume BitLocker's disk-level protection may be insufficient
Long-term:
## Related Coverage