This worrying Microsoft BitLocker backdoor can give full access to a locked drive – and all you need is a USB stick


  • Chaotic Eclipse leaks two new Windows bugs: YellowKey (BitLocker bypass) and GreenPlasma (privilege escalation)
  • YellowKey abuses WinRE to bypass BitLocker; verified by Kevin Beaumont, although mitigations are discussed
  • GreenPlasma leverages CTFMON services for SYSTEM access; follows previous leaks RedSun, UnDefend and BlueHammer (later fixed as CVE-2026-33825)

Chaotic Eclipse, the security researcher who recently leaked three unpatched Windows vulnerabilities because they were unhappy with how Microsoft handles bug reports, has now leaked two more bugs along with proof-of-concepts (PoC) showing how they could be exploited.

In their latest release, Chaotic Eclipse revealed bugs named YellowKey and GreenPlasma. The former is a BitLocker bypass, while the latter is a privilege escalation vulnerability.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top