A newly discovered zero-day exploit, dubbed GreatXML, can bypass BitLocker encryption in just four hours of research, granting attackers a SYSTEM shell in Recovery Mode. This vulnerability is particularly concerning as it can be exploited on any machine that has run an offline Microsoft Defender scan, with no existing patch available to mitigate the issue. The GreatXML exploit was accidentally discovered by security researcher Chaotic Eclipse, who also recently published another exploit called RoguePlanet, targeting Microsoft Defender for local privilege escalation. The fact that this exploit can be used to unlock BitLocker in such a short amount of time is alarming, and its existence highlights the need for immediate assessment of exposure to this vulnerability1. This matters to security practitioners because the window for patching Microsoft vulnerabilities is rapidly shrinking, making it essential to evaluate their systems' vulnerability to this exploit.
Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research
⚠️ Critical Alert
Why This Matters
Zero-day activity targeting Microsoft means patching windows are already closing — assess your exposure immediately.
References
- SecurityAffairs. (2024 is incorrect, using 2026 instead). (2026, June 11). Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research. *SecurityAffairs*. https://securityaffairs.com/193516/security/chaotic-eclipse-strikes-again-new-zero-day-unlocks-bitlocker-in-four-hours-of-research.html
Original Source
SecurityAffairs
Read original →