ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files

criticalExploit / PoCimportance 60CVE-2026-45585

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-45585
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey".

Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available. Mitigation FAQs Should I leverage the temporary mitigation? Microsoft recommends that you consider implementing these mitigations if you are concerned your devices and data are at risk of being compromised or stolen. For example, if your organization’s employees take their work devices home or on business travel. What impact to service availability/management could be caused by implementing the mitigations? Implementing these mitigations will not impact service availability or management operations. Do customers need to revert the changes made to mitigate the vulnerability once the security update to protect against this vulnerability is available? No. The security update will maintain the mitigation's behavior once the security update is installed. I am using TPM+PIN, am I at risk of this vulnerability being exploited No, if you are using TPM+PIN the vulnerability is not exploitable.

NVD description · AI analysis pending
6.81% PoC
  • microsoft windows 11 24h2
  • microsoft windows 11 25h2
  • microsoft windows 11 26h1
  • +1 more
Full article522 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJun 11, 2026Endpoint Security / Vulnerability

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day after they published an exploit for Microsoft Defender.

"This was an accidental discovery, it took a total of 4 hours to find this," the researcher said in a post on Blogger. "If you ever attempted to use Windows Defender Offline Scan, you're automatically vulnerable to a BitLocker bypass. I'm unsure if you can still trigger the bug without ever using the offline scan feature, because you can definitely."

The exploit works as follows -

  • Copy an XML file ("unattend.xml") and a recovery folder containing another XML file ("Recovery/WindowsRE/ReAgent.xml") to the root of the recovery partition.
  • Reboot to Windows Recovery Environment (WinRE) by holding Shift while clicking Restart in the Windows power menu.

If every step is followed correctly, the result is a shell spawned with unrestricted access to the BitLocker volume.

"If Defender offline scan was never initiated then you have to either login and initiate it yourself or figure out a way to boot into WinRE in offline scan state (I believe it should be very possible to do so without logging in) and follow steps above," Chaotic Eclipse noted.

In a post on Mastodon, security researcher Will Dormann opined the steps to reproduce GreatXML as "flawed," adding triggering a Microsoft Defender Offline Scan requires a user to be both logged in to Windows and have admin credentials, at which point it's trivial to turn off BitLocker anyway.

"The writeup for GreatXML suggests that the prerequisite is that Windows Defender Offline has been executed at some point in the past," Dorman added. "And that after planting two files in WinRE, all you need to do is [Shift]-reboot into WinRE, and Windows will automatically go into Microsoft Defender Offline scan mode. But this is not the case in any of the 3 lineages of Win11 that I have handy."

The release of GreatXML comes not long after RoguePlanet, a zero-day flaw in Microsoft Defender that facilitates local privilege escalation (LPE) to SYSTEM, granting the attacker the ability to run arbitrary code or perform unauthorized actions.

GreatXML is also the second BitLocker bypass released by Chaotic Eclipse after YellowKey (aka CVE-2026-45585), patches for which were released by Microsoft this week as part of Patch Tuesday updates.

Update

When reached for comment, a Microsoft spokesperson shared the below statement with The Hacker News -

Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public.

(The story was updated after publication on June 16, 2026, to include a response from Microsoft.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/06/new-greatxml-exploit-bypasses-windows.html