HomeSecurityNew YellowKey vulnerability bypasses BitLocker

New YellowKey vulnerability bypasses BitLocker

An anonymous cybersecurity researcher, who previously disclosed three vulnerabilities in Microsoft Defender, is back with two new zero-day discoveries affecting critical Windows. The vulnerabilities, codenamed YellowKey and GreenPlasma, involve BitLocker bypass and local privilege escalation in the Windows Collaborative Translation Framework (CTFMON), generating intense interest in the cybersecurity community due to their potential impact on enterprise and government environments.

BitLocker YellowKey

YellowKey and the unexpected BitLocker bypass

The YellowKey is considered by the researcher to be one of his most unusual and complex discoveries, as it appears to exploit mechanisms in the Windows Recovery Environment (WinRE). WinRE is a critical Windows subsystem used to repair systems that fail to boot normally, but in this case it appears to be becoming a potential entry point for attacks that bypass BitLocker.

YellowKey affects Windows 11 and Windows Server 2022/202. According to the technical details, the exploit involves using specially crafted FsTx files, which are placed on USB devices or the EFI partition. The USB drive is then connected to the target computer with BitLocker protections enabled, rebooted into WinRE, and launched a shell while holding down the CTRL key.

See also: Microsoft: Windows 10 WinRE update with BitLocker fixes

WinRE and TPM security concerns

The researcher points out that even protection combinations, such as TPM+PIN, do not seem to prevent exploitation. The complexity of the issue has led to difficulties in fully understanding the bug by Microsoft itself, while extensive analysis is expected from the MSRC team.

Of particular interest is the observation of independent researchers such as Will Dormann, who managed to reproduce the problem and noted that Transactional NTFS bits can affect files on different disks and delete critical boot files.

New YellowKey vulnerability bypasses BitLocker

GreenPlasma and the Windows CTFMON Framework

The second vulnerability, known as GreenPlasma, concerns the Windows Collaborative Translation Framework (CTFMON) and is related to local privilege escalation up to SYSTEM level. The issue appears to arise from the possibility of creating arbitrary memory section objects within directories that are normally only accessible by privileged processes.

Although the available proof-of-concept is still incomplete, the basic idea of ​​the exploit is based on manipulating shared memory structures used by CTFMON to handle keyboard input and language services. In a successful attack scenario, a simple user could affect services running with SYSTEM privileges, paving the way for complete control of the system.

See also: MDASH: Microsoft's new AI system finds 16 vulnerabilities in Windows

The risks for Windows enterprise environments

The existence of such vulnerabilities in key Windows subsystems raises concerns for organizations that rely on BitLocker for physical device security and CTFMON for critical user interface functions. In corporate environments, successful exploitation could allow not only access to encrypted data, but also complete compromise of endpoint systems without detection.

CHwapi- Windows BitLocker-hospital Belgium

What should IT admins practically do to deal with YellowKey?

1) Take inventory of which endpoints are BitLocker TPM-only
– high-risk laptops (C-level, admins, mobile workers) first.

2) Put TPM+PIN where possible
– it will have a small operational cost (PIN at startup), but significantly increases the difficulty for a physical attacker.

3) Restrict booting from USB/external media and harden UEFI
– active Secure Boot, strong UEFI password, disable external boot options where possible.

4) If you implement WinRE mitigation, organize rollout properly
– it is a process that touches recovery images and registry hives: it requires change management, testing, backup and rollback.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What does it mean for Greece/businesses/admins/users?

For Greek businesses and government organizations that rely on BitLocker as a baseline for mobile device protection, YellowKey reminds us that physical access scenarios remain critical: laptop theft, loss while traveling, or access to a workplace. For IT admins in Greece, the practical move today is to evaluate BitLocker policies (TPM-only vs TPM+PIN), check WinRE posture, and restrict external boot.

Broader threat landscape and zero-day market

The emergence of YellowKey and GreenPlasma comes at a time of heightened activity in the so-called zero-day exploit market, where high-value vulnerabilities are traded for particularly high amounts of money. The targeting of Windows components such as WinRE shows a trend of attacks shifting to deeper levels of the operating system, where traditional protection mechanisms have difficulty intervening.

See also: Windows 11 Low Latency Profile: New speed boost feature

Although both vulnerabilities are still under investigation and have not been widely exploited in the field, their severity has already mobilized Microsoft and the research community. The need to review critical isolation mechanisms in WinRE and CTFMON is becoming increasingly apparent, while organizations are urged to immediately implement hardening and monitoring practices. In an environment where zero-day attacks evolve faster than fixes, proactive security remains the most powerful tool for defense.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS