YellowKey backdoor (from Microsoft?) in BitLocker

A researcher known as “Nightmare-Eclipse” recently released the YellowKey, a security flaw that allows BitLocker encryption to be completely bypassed. The researcher describes YellowKey as one of the “craziest” flaws he has ever encountered and accuses Microsoft of possibly incorporating a legitimate backdoor into BitLocker’s data protection system.

According to the researcher, YellowKey seems unusual for a security flaw. Nightmare-Eclipse reports that the vulnerability can be replicated by copying an attached “FsTx” folder to a USB drive formatted with a Windows-compatible file system, such as NTFS, FAT32, or exFAT.

See more articles from iGuRu.gr when you search for news on Google.

The vulnerability can also work without USB if the FsTx files are copied to the Windows EFI partition and the encrypted drive is temporarily disconnected from the system. After mounting the FsTx folder, an attacker would need to reboot a BitLocker-protected machine, enter the Windows Recovery Environment, and follow a specific sequence.

If the process is completed correctly, a command shell appears, which provides unrestricted access to BitLocker-protected drives. No passwords are required, and encrypted data can be made fully accessible for browsing, copying, and other file operations.

Nightmare-Eclipse believes that the YellowKey vulnerability could reasonably be considered a backdoor intentionally added to BitLocker by Microsoft. Their reasoning is that the component that triggers the problem can only be found in the official WinRE image. The same component is also present in standard Windows installation images, but it does not exhibit the BitLocker bypass behavior seen on live systems.

The researcher stated that he “cannot find an explanation other than the fact that the security hole is intentional. Also, for some reason, only Windows 11 (+Server 2022/2025) is affected, Windows 10 is not.”

Other researchers confirm that YellowKey behaves as described by Nightmare-Eclipse on GitHub. In addition, the researcher released a second exploit, GreenPlasma, which allows privilege escalation. He did not publish the full proof-of-concept for achieving SYSTEM-level access, but said he may reveal more details before next month's Patch Tuesday.

Nightmare-Eclipse is known for targeting Microsoft, and previously operated under the alias “ Chaotic Eclipse “.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).