BitLocker Zero-Day Exploits Leave Windows 11 Systems Exposed
Want more insights like this?
A security researcher released two Windows zero-day exploits on GitHub on May 13, after a dispute with Microsoft over its handling of their earlier reports. The more serious, "YellowKey", uses a crafted folder on a USB stick or the EFI partition to bypass BitLocker on Windows 11 and Server 2022/2025 in minutes — with physical access.
The public exploit only works against TPM-only BitLocker, which auto-unlocks at boot; it fails against TPM+PIN. The researcher says he has a version that defeats PIN setups too and is withholding it. Windows 10 is unaffected — its recovery architecture differs.
The second exploit, "GreenPlasma", targets the CTFMON service, but the released code is deliberately incomplete — it triggers a UAC prompt by default and lacks the piece needed for a SYSTEM shell. The researcher left that to whoever wants it.
Microsoft says it's investigating and hasn't patched either. A BitLocker PIN plus a BIOS password, per Kevin Beaumont, is the practical mitigation. Treat it as urgent: this researcher's April drops, RedSun and UnDefend, were weaponized in real attacks within days, per Huntress.
Updated August 13, 2026: Microsoft patched YellowKey and GreenPlasma on June 9, 2026, in the same Patch Tuesday that fixed the researcher's MiniPlasma flaw.
Source: Cyber Security News