Switch language한국어
Back to the list

Vulnerability Revealed That Lets BitLocker-Protected Drives Be Accessed Using Only Files on a USB Memory Stick Without a Recovery Key

TL;DR AI

Key summary

2 min read
  1. Researcher Nightmare-Eclipse disclosed YellowKey, a zero-day that may bypass BitLocker on some Windows systems using a USB drive and physical access.

  2. The flaw reportedly affects certain Windows 11 and Windows Server versions, potentially exposing data on stolen or unattended devices.

  3. Nightmare-Eclipse also published GreenPlasma, a separate Windows privilege-escalation vulnerability that could lead to SYSTEM-level access.

  4. The findings raise concern because BitLocker is widely used to protect Windows endpoints, especially when combined with other local attack paths.

Read the original