Briefing

YellowKey Zero‑Day Bypasses Windows 11 BitLocker

security
by [email protected] (The Hacker News) ·

Patch Microsoft Defender immediately to mitigate YellowKey and GreenPlasma zero‑days.

What to do now

Patch Microsoft Defender immediately.

Summary

A newly disclosed zero‑day vulnerability, dubbed YellowKey, allows an attacker with physical access to a Windows 11 machine to bypass the operating system’s default BitLocker full‑volume encryption. The flaw exploits the way Windows 11 stores the BitLocker key in the trusted platform module (TPM), enabling the attacker to decrypt the disk without the user’s decryption key. The exploit was first publicised by security researcher Nightmare‑Eclipse earlier this week and has already been highlighted by prominent security outlets such as Ars Technica and Slashdot.

BitLocker is a core data‑at‑rest protection feature used by many enterprises and government agencies, and its reliance on TPM for key storage is intended to provide a hardware‑based barrier against tampering. YellowKey undermines this barrier by taking advantage of a weakness in the TPM‑based key handling process. Because the attack requires only physical proximity to the device, it poses a significant risk to organisations that store sensitive data on Windows 11 laptops or servers, especially those that rely on BitLocker as a primary defence.

Microsoft has not yet issued a specific patch for YellowKey, but the company typically addresses such vulnerabilities through its regular cumulative updates. Security experts advise that organisations running Windows 11 should immediately install the latest cumulative update once it becomes available, and that physical security controls remain a critical line of defence. Until a patch is released, the best mitigation is to restrict physical access to devices that contain critical data.

The discovery of YellowKey has prompted a broader discussion within the security community about the limits of hardware‑based encryption and the need for layered security strategies. While the exploit does not compromise the encryption algorithm itself, it demonstrates that even trusted hardware modules can be subverted if the software interface is flawed. As Microsoft works on a fix, the incident serves as a reminder that zero‑day vulnerabilities can expose even the most robust security features, underscoring the importance of timely patching and comprehensive physical security measures.

Key changes

  • YellowKey zero‑day enables BitLocker bypass
  • GreenPlasma zero‑day grants privilege escalation in CTFMON
  • Both vulnerabilities are active and unpatched
  • Researcher Chaotic Eclipse disclosed the flaws
  • Microsoft Defender is the affected product

Affects

internal

Source angles · 2 perspectives

The Hacker News
Independent angle

Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation

Open
Schneier on Security
Independent angle

YellowKey Zero‑Day Exploit Bypasses Windows 11 BitLocker

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting