A newly disclosed BitLocker bypass vulnerability (dubbed YellowKey) affects Windows 11, Server 2022, and Server 2025. By placing specific files from a FsTx folder onto a USB stick or EFI partition, then rebooting into the Windows Recovery Environment while holding CTRL, an attacker can spawn a shell with unrestricted access to a BitLocker-protected volume. The researcher notes the responsible component exists only inside WinRE images and behaves differently from its counterpart in normal Windows installations, raising suspicions of an intentional backdoor. Windows 10 is reportedly not affected. The disclosure was coordinated with Microsoft's MORSE, MSTIC, and GHOST teams.
12 Impressions