This Worrying Microsoft BitLocker Backdoor Can Grant Full Access to a Locked Drive, and All You Need is a USB Stick



  • Chaotic Eclipse leaks two new Windows bugs: YellowKey (BitLocker bypass) and GreenPlasma (privilege escalation)
  • YellowKey abuses WinRE to bypass BitLocker; verified by Kevin Beaumont, although mitigations are debated
  • GreenPlasma exploits CTFMON services to access the SYSTEM; follows previous leaks from RedSun, UnDefend and BlueHammer (later patched as CVE-2026-33825)

Chaotic Eclipse, the security researcher who recently leaked three unpatched Windows vulnerabilities because he was unhappy with the way Microsoft handles bug reports, has now leaked two more flaws, along with proofs of concepts (PoCs) showing how they could be exploited.

In its latest release, Chaotic Eclipse revealed flaws called YellowKey and GreenPlasma. The first is a BitLocker bypass, while the second is a privilege escalation vulnerability.

Leave a Comment

Your email address will not be published. Required fields are marked *