Vulnerability Revealed That Lets BitLocker-Protected Drives Be Accessed Using Only Files on a USB Memory Stick Without a Recovery Key

TL;DR AI
2 min readKey summary
Researcher Nightmare-Eclipse disclosed YellowKey, a zero-day that may bypass BitLocker on some Windows systems using a USB drive and physical access.
The flaw reportedly affects certain Windows 11 and Windows Server versions, potentially exposing data on stolen or unattended devices.
Nightmare-Eclipse also published GreenPlasma, a separate Windows privilege-escalation vulnerability that could lead to SYSTEM-level access.
The findings raise concern because BitLocker is widely used to protect Windows endpoints, especially when combined with other local attack paths.


