{"id":1278,"date":"2026-06-11T19:51:55","date_gmt":"2026-06-11T19:51:55","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1278"},"modified":"2026-06-11T19:51:55","modified_gmt":"2026-06-11T19:51:55","slug":"new-greatxml-exploit-bypasses-windows-bitlocker-via-recovery-partition-xml-files","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1278","title":{"rendered":"New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 11, 2026<\/span><\/span><span class=\"p-tags\">Endpoint Security \/ Vulnerability<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqKyNLbT9WYm7m6ZsvIgv0mNbGJCrgEjUUXLbRZV9mmQUVi7jT9IiwlXh2kYKiMOrsCnJ-ZaoAK9GnL9jy6RHJELISIGFuLSZgsSYuclWFcPmItYL04pTVeA7cl_jy8L6RU4CVPypa6u24OH8hCwPL1g1tEVRczTV1YjZ5KUFGZc6DVw8Pdo_CFGXRTS-d\/s1700-e365\/windows-bitlocker.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed <b><a href=\"https:\/\/github.com\/MSNightmare\/GreatXML\">GreatXML<\/a><\/b>, a day after they published an exploit for Microsoft Defender.<\/p>\n<p>\u00abThis was an accidental discovery, it took a total of 4 hours to find this,\u00bb the researcher <a href=\"https:\/\/deadeclipse666.blogspot.com\/2026\/06\/greatxml-bitlocker-that-seems-to-only.html\">said<\/a> in a post on Blogger. \u00abIf you ever attempted to use Windows Defender Offline Scan, you&#8217;re automatically vulnerable to a BitLocker bypass. I&#8217;m unsure if you can still trigger the bug without ever using the offline scan feature, because you can definitely.\u00bb<\/p>\n<p>The exploit works as follows &#8211;<\/p>\n<ul>\n<li>Copy an XML file (\u00abunattend.xml\u00bb) and a recovery folder containing another XML file (\u00abRecovery\/WindowsRE\/ReAgent.xml) to the root of the recovery partition.<\/li>\n<li>Reboot to Windows Recovery Environment (<a href=\"https:\/\/support.microsoft.com\/en-us\/windows\/windows-recovery-environment-0eb14733-6301-41cb-8d26-06a12b42770b\">WinRE<\/a>) by holding Shift while clicking Restart in the Windows power menu.<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>If every step is followed correctly, the result is a shell spawned with unrestricted access to the BitLocker volume.<\/p>\n<p>\u00abIf Defender offline scan was never initiated then you have to either login and initiate it yourself or figure out a way to boot into WinRE in offline scan state (I believe it should be very possible to do so without logging in) and follow steps above,\u00bb Chaotic Eclipse noted.<\/p>\n<p>The release of GreatXML comes not long after RoguePlanet, a zero-day flaw in Microsoft Defender that facilitates local privilege escalation (LPE) to SYSTEM, granting the attacker the ability to run arbitrary code or perform unauthorized actions.<\/p>\n<p>GreatXML is also the second BitLocker bypass released by Chaotic Eclipse after YellowKey (aka CVE-2026-45585), patches for which were released by Microsoft this week as part of Patch Tuesday updates.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 11, 2026Endpoint Security \/ Vulnerability Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day after they published an&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1279,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1668,889,120,236,2012,2013,1050,307,2014],"class_list":["post-1278","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-bitlocker","tag-bypasses","tag-exploit","tag-files","tag-greatxml","tag-partition","tag-recovery","tag-windows","tag-xml"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1278","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1278"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1278\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1279"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1278"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1278"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1278"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}