Skip to main content
Newsletter IconGoogle IconFacebook IconX IconInstagram IconYouTube Icon

Security researcher finds zero-day exploit that defeats Windows 11 BitLocker, calls it an insane 'backdoor' discovery

Users who rely solely on TPM-based BitLocker are most at risk, while those with a PIN or USB security key at boot are generally better protected.

Security researcher finds zero-day exploit that defeats Windows 11 BitLocker, calls it an insane 'backdoor' discovery
Facebook IconX IconReddit Icon
Comments
Senior Tech Reporter
Published
1 minute & 30 seconds read time
TL;DR: The YellowKey zero-day exploit lets anyone with physical access bypass Windows 11's default BitLocker encryption via a WinRE vulnerability, granting full drive access without a recovery key. It affects only Windows 11 and certain servers, while additional boot authentication methods offer better protection.
Voice: Hassam Nasir
0:00 / 3:04
Use left and right arrow keys to seek audio.

A security researcher going by the alias Nightmare-Eclipse has uncovered a zero-day exploit they describe as one of the most insane discoveries ever, saying it "almost feels like a backdoor." Dubbed YellowKey, the exploit allows anyone with physical access to a Windows 11 system to bypass default BitLocker protections and gain complete access to an encrypted device within seconds.

BitLocker is Microsoft's full-volume encryption that protects storage disks and their contents from anyone without the decryption key. That key is stored in a Trusted Platform Module (TPM), and BitLocker is a mandatory protection for many organizations, including government contractors.

Popular Now: Redditor buys an RTX 5070 Ti for $1,099 from Walmart, receives four graphics cards instead

The researcher refers to it as a backdoor because the bug appears only in WinRE (Windows Recovery Environment) and not in Windows itself, which lacks the required functionality needed to trigger the bypass. Additionally, the bypass affects only Windows 11, Windows Server 2022, and Windows Server 2025 systems with the default BitLocker configuration, while Windows 10 machines are unaffected.

Security researcher finds zero-day exploit that defeats Windows 11 BitLocker, calls it an insane 'backdoor' discovery 1

The core of the YellowKey exploit involves a custom-made FsTx folder that provides transactional atomicity for file operations. An attacker only needs to copy the FsTx folder to a specific path on a recovery drive, boot into WinRE, and follow a simple key sequence. This opens a command prompt with full access to the entire drive's contents, allowing an attacker to copy, modify, or delete files. Normally, at this stage, a BitLocker recovery key would be required, but YellowKey bypasses that safeguard entirely.

Multiple researchers have confirmed the exploit works as described, though researcher @KevTheHermit on X notes it can be inconsistent and may require repeated attempts. The same researcher also released a second exploit, GreenPlasma, which is said to enable privilege escalation to the SYSTEM level by abusing trusted paths used by services and kernel drivers. Full proof-of-concept code was not published due to the potential for severe abuse.

That said, YellowKey only works with Windows 11's default BitLocker configuration, in which decryption keys are stored solely in the TPM. Users who rely on additional authentication at boot, such as a PIN or USB security key, are generally better protected against this kind of attack.

Photo of the Dell 16 Windows 11 Home Copilot+ Laptop

Best Deals: Dell 16 Windows 11 Home Copilot+ Laptop

* Prices may be inaccurate. As an Amazon Associate, we earn from qualifying purchases. We earn affiliate commissions from Newegg and PCCG sales.

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

News Source:github.com

Comments

About the author

Senior Tech Reporter

Hassam is a veteran tech journalist and editor with over eight years of experience embedded in the consumer electronics industry. His obsession with hardware began with childhood experiments involving semiconductors, a curiosity that evolved into a career dedicated to deconstructing the complex silicon that powers our world. From benchmarking PC internals to stress-testing flagship CPUs and GPUs, Hassam specializes in translating high-level engineering into deep, unbiased insights for the enthusiast community.

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Follow TweakTown on GoogleAdd TweakTown as a preferred source on Google
Newsletter Subscription