{"id":915,"date":"2026-05-14T10:14:03","date_gmt":"2026-05-14T10:14:03","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=915"},"modified":"2026-05-14T10:14:03","modified_gmt":"2026-05-14T10:14:03","slug":"windows-zero-days-expose-bitlocker-bypasses-and-ctfmon-privilege-escalation","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=915","title":{"rendered":"Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgXt7ooDl2PwJY4nazAKdW9rmILsmosve2FZaO9usxTk_rkksEEvsLgY-uc_MErXvjvusuWjN7PWRM9KaRXB1OkL75gio7tcqpMsPZxaFNE9XDpYmARH3Dw_gGgddwWXHSt5VUJ-lb56F9bCVzTYghEo7qELWVv8K_W8V1BrWgssgqWkzPJxW6I31i_GyYf\/s1700-e365\/windowss.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>An anonymous cybersecurity researcher who disclosed three Microsoft Defender vulnerabilities has returned with two more zero-days involving a BitLocker bypass and a privilege escalation impacting Windows Collaborative Translation Framework (CTFMON).<\/p>\n<p>The <a href=\"https:\/\/deadeclipse666.blogspot.com\/2026\/05\/two-more-public-disclosures-it-will.html\">security defects<\/a> have been codenamed <strong><a href=\"https:\/\/github.com\/Nightmare-Eclipse\/YellowKey\">YellowKey<\/a><\/strong> and <strong><a href=\"https:\/\/github.com\/Nightmare-Eclipse\/GreenPlasma\">GreenPlasma<\/a><\/strong>, respectively, by the researcher, who goes by the online aliases Chaotic Eclipse and Nightmare-Eclipse.<\/p>\n<p>The researcher described <a href=\"https:\/\/x.com\/weezerOSINT\/status\/2054299771817660433\">YellowKey<\/a> as \u00abone of the most insane discoveries I ever found,\u00bb likening the BitLocker bypass to functioning as a backdoor, as the bug is present only in the Windows Recovery Environment (<a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/manufacture\/desktop\/windows-recovery-environment--windows-re--technical-reference\">WinRE<\/a>), a built-in framework designed to troubleshoot and repair common unbootable operating system issues.<\/p>\n<p>YellowKey affects Windows 11 and Windows Server 2022\/2025. At a high level, it involves copying specially crafted \u00abFsTx\u00bb files on a USB drive or the EFI partition, plugging the USB drive into the target Windows computer with BitLocker protections turned on, rebooting into WinRE, and triggering a shell by holding down the CTRL key.<\/p>\n<p>\u00abI think it will take a while even for MSRC to find the real root cause of the issue. I just never managed to understand why this vulnerability is sooo well hidden,\u00bb the researcher <a href=\"https:\/\/deadeclipse666.blogspot.com\/2026\/05\/were-doing-silent-patches-now-huh-also.html\">explained<\/a>. \u00abSecond thing is, no, TPM+PIN does not help, the issue is still exploitable regardless.\u00bb<\/p>\n<p>Security researcher Will Dormann, in a <a href=\"https:\/\/infosec.exchange\/@wdormann\/116565129854382214\">post<\/a> shared on Mastodon, said, \u00abI was able to reproduce [YellowKey] with a USB drive attached,\u00bb adding, \u00abit looks like Transactional NTFS bits on a USB Drive are able to delete the winpeshl.ini file on ANOTHER DRIVE (X:). And we get a cmd.exe prompt, with BitLocker unlocked instead of the expected Windows Recovery environment.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abWhile the <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/security\/operating-system-security\/data-protection\/bitlocker\/countermeasures\">TPM-only BitLocker<\/a> bypass is indeed interesting, I think the buried lede here is that a \\System Volume Information\\FsTx directory on one volume has the ability to modify the contents of another volume when it is replayed,\u00bb Dormann pointed out. \u00abTo me, this in and of itself sounds like a vulnerability.\u00bb<\/p>\n<p>The second vulnerability flagged by Chaotic Eclipse is a case of privilege escalation security that could be exploited to obtain a shell with SYSTEM permissions. It arises as a result of what has been described as Windows CTFMON arbitrary section creation.<\/p>\n<p>The released proof-of-concept (PoC) is incomplete and lacks the necessary code to obtain a full SYSTEM shell. In its current form, the exploit can allow an unprivileged user to create arbitrary memory section objects within directory objects writable by SYSTEM, potentially enabling manipulation of privileged services or drivers that implicitly trust those paths, as a standard user does not have write access to the locations.<\/p>\n<p>The development comes nearly a month after the researcher <a href=\"https:\/\/thehackernews.com\/2026\/04\/three-microsoft-defender-zero-days.html\">published three Defender zero-days dubbed BlueHammer, RedSun, and UnDefend after allegedly expressing dissatisfaction with Microsoft&#8217;s handling of the vulnerability disclosure process. The shortcomings have since come under active exploitation in the wild.<\/p>\n<p>While BlueHammer was officially assigned the identifier CVE-2026-33825 and patched by Microsoft last month, Chaotic Eclipse said the tech giant appears to have \u00absilently\u00bb addressed RedSun without issuing any advisory.<\/p>\n<p>\u00abI hope you at least attempt to resolve the situation responsibly, I&#8217;m not sure what type of reaction you expected from me when you threw more gas on the fire after BlueHammer,\u00bb the researcher said. \u00abThe fire will go as long as you want, unless you extinguish it or until there nothing left to burn.\u00bb<\/p>\n<p>Chaotic Eclipse also promised a \u00abbig surprise\u00bb for Microsoft, coinciding with the next Patch Tuesday release in June 2026.<\/p>\n<p>When reached for comment, a Microsoft spokesperson had previously told The Hacker News that it \u00abhas a customer commitment to investigate reported security issues and update impacted devices to protect customers as soon as possible,\u00bb and that it supports coordinated vulnerability disclosure, which the company said \u00abhelps ensure issues are carefully investigated and addressed before public disclosure.\u00bb<\/p>\n<h3>BitLocker Downgrade Attack Uncovered<\/h3>\n<p>The development comes as French cybersecurity company Intrinsec detailed an <a href=\"https:\/\/github.com\/garatc\/BitUnlocker\">attack chain<\/a> against BitLocker that leverages a boot manager downgrade by exploiting CVE-2025-48804 (CVSS score: 6.8) to bypass the encryption protection on fully patched Windows 11 systems in under five minutes.<\/p>\n<p>\u00abThe principle is as follows: the boot manager loads the System Deployment Image (SDI) file and the WIM referenced by it, and verifies the integrity of the legitimate WIM,\u00bb Intrinsec <a href=\"https:\/\/www.intrinsec.com\/en\/contournement-bitlocker-la-realite-des-downgrade-attacks\/\">said<\/a>.<\/p>\n<p>\u00abHowever, when a second WIM is added to the SDI with a modified blob table, the boot manager checks the first (legitimate) WIM while simultaneously booting from the second (controlled by the attacker). This second WIM contains a WinRE image infected with &#8216;cmd.exe,&#8217; which executes with the decrypted BitLocker volume.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>While fixes released by Microsoft in July 2025 plugged this security defect in July 2025, security researcher Cassius Garat said the problem lies in the fact that Secure Boot only verifies a binary&#8217;s signing certificate, not its version. As a result, a vulnerable version of \u00abbootmgfw.efi\u00bb that does not contain the patch and is signed with the trusted PCA 2011 certificate can be used to get around BitLocker safeguards.<\/p>\n<p>It&#8217;s worth noting that Microsoft plans to retire the old PCA 2011 certificates next month. \u00abAnd as long as it is not revoked, even an old, vulnerable boot manager can be loaded without triggering an alert,\u00bb Intrinsec noted. To pull off the attack, a bad actor needs to have physical access to the target machine.<\/p>\n<p>To counter the risk, it&#8217;s essential to enable a <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/security\/operating-system-security\/data-protection\/bitlocker\/countermeasures#preboot-authentication\">BitLocker PIN<\/a> at startup for <a href=\"https:\/\/www.intrinsec.com\/en\/contournement-bitlocker-alternative-tpm-sniffing\/\">preboot authentication<\/a> and migrate the boot manager to the <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d\">CA 2023 certificate<\/a> and revoke the old PCA 2011 certificate.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>An anonymous cybersecurity researcher who disclosed three Microsoft Defender vulnerabilities has returned with two more zero-days involving a BitLocker bypass and a privilege escalation impacting Windows Collaborative Translation Framework (CTFMON).&hellip;<\/p>\n","protected":false},"author":1,"featured_media":916,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1668,889,1669,306,918,305,307,53],"class_list":["post-915","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-bitlocker","tag-bypasses","tag-ctfmon","tag-escalation","tag-expose","tag-privilege","tag-windows","tag-zerodays"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/915","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=915"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/915\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/916"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=915"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=915"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}