INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Windows Zero-Days Expose BitLocker Bypasses

| 2026-05-14 09:25 CRITICAL HIGH
Executive Summary AI-generated
The recent incident data reveals a sophisticated attack exploiting vulnerabilities in Windows, specifically the BitLocker bypass and privilege escalation capabilities. The researcher behind this discovery has returned with two more zero-days involving these same tactics, affecting multiple Microsoft Defender vulnerabilities. This case highlights the importance of patching systems to prevent exploitation by attackers like Chaotic Eclipse.
Technical Mitigations AI-generated
* Use of Transactional NTFS: Implementing transactional NTFS can help prevent the deletion of sensitive files, such as winpeshl.ini, which is used by BitLocker to store encrypted data. * Implement a secure boot process: Ensuring that the system boots with a trusted and validated operating system can help prevent exploitation of vulnerabilities like YellowKey and GreenPlasma. * Use a secure file system: Using a secure file system, such as Veritas Volume Shadowing or Microsoft's BitLocker-encrypted volume, can provide an additional layer of protection against unauthorized access to protected drives. * Implement a TPM+PIN requirement: Requiring users to use both the Trusted Platform Module (TPM) and a PIN code for encryption can help prevent exploitation of vulnerabilities like YellowKey and GreenPlasma that rely on these security features. * Regularly update and patch systems: Keeping software up-to-date with the latest security patches can help reduce the risk of exploitation by mitigating known vulnerabilities, such as those found in Windows 11 and Server 2022/2025.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-33825CVE-2026-33825 CVE-2025-48804CVE-2025-48804
Target & Sectors
Global Scope
Incident Timeline
‎CA 2023
Threat actors exploited a Windows Zero-Day vulnerability to bypass BitLocker and target systems using the CTFMON privilege escalation tool.
‎July 2025
Threat actors exploited a vulnerability in the Windows boot loader to bypass BitLocker safeguards by using an outdated version of "bootmgfw.efi" signed with a trusted PCA 2011 certificate.
‎2026/04/14
Threat actors used Microsoft's patch for CVE-2026-33825 to bypass Windows Zero-Days.
organisation CVE-2026-33825
‎May 12
Threat actors exploited Windows zero-days to bypass BitLocker and used CTFMON privilege escalation techniques.
organisation the Autonomous Validation Summit
general_metric 14 May
‎2026/05/13
Threat actors exploited a Windows Zero-Day vulnerability to bypass BitLocker encryption and escalate privileges in a targeted environment.
organisation Chaotic Eclipse
‎2022/2025
Threat actors used YellowKey to exploit a Windows Zero-Day vulnerability and bypass the BitLocker encryption system.
infrastructure Windows
organisation YellowKey
tactic T1584.004 - Server
general_metric 11 Windows
‎2026/05/14
The security researcher disclosed two Microsoft Windows vulnerabilities, YellowKey and GreenPlasma, which are a BitLocker bypass and a privilege-escalation flaw.
infrastructure Windows
organisation BitLocker Bypasses
organisation CTFMON Privilege Escalation
organisation Microsoft Defender
organisation BitLocker
organisation Windows Collaborative Translation Framework
organisation CTFMON
organisation CVE-2026-33825
organisation BlueHammer
organisation LPE
organisation the Windows Recovery Environment
organisation USB
organisation EFI
organisation WinRE
organisation PoC
organisation YellowKey
organisation GreenPlasma
organisation Microsoft Windows
organisation Nightmare
organisation BleepingComputer
organisation NTFS
organisation Mastodon
organisation Transactional NTFS
organisation Chaotic Eclipse
organisation MSRC
organisation RedSun
organisation Microsoft
organisation Chaotic/Nightmare Eclipse
organisation BitLocker PIN
organisation Tharros Labs
organisation FsTx
organisation Dormann
organisation TPM
organisation Chaotic Eclypse's
‎June 2026
Chaotic Eclipse exploited a CVE-2025-48804 vulnerability in Windows 11 to downgrade the boot manager and bypass BitLocker encryption.
infrastructure Windows
organisation CVE-2025-48804
organisation Intrinsec
organisation The Hacker News
organisation the System Deployment Image
organisation WIM
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Intelligence Sources