Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Security researcher Chaotic Eclipse has published two new zero-day exploits targeting Windows. The first, YellowKey, bypasses BitLocker encryption entirely by copying specific files to a USB stick and rebooting into the Windows Recovery Environment — no keys required. The exploit works on Windows 11, Server 2022, and Server 2025, and its files self-delete after use, raising backdoor suspicions. The second, GreenPlasma, achieves system-level privilege escalation by manipulating the CTFMon process. The researcher published these after Microsoft allegedly dismissed prior vulnerability disclosures. As of publication, Microsoft has not officially responded to either exploit.