Zero-day exploit completely defeats default Windows 11 BitLocker protections



A zero-day exploit circulating online allows people with physical access to a Windows 11 system to bypass default BitLocker protections and gain complete access to an encrypted drive within seconds.

The exploit, named YellowKey, was published earlier this week by a researcher who goes by the alias Nightmare-Eclipse. It reliably bypasses default Windows 11 deployments of BitLocker, the full-volume encryption protection Microsoft provides to make disk contents off-limits to anyone without the decryption key, which is stored in a secured piece of hardware known as a trusted platform module (TPM). BitLocker is a mandatory protection for many organizations, including those that contract with governments.

When one disk volume manipulates another

The core of the YellowKey exploit is a custom-made FsTx folder. Online documentation of this folder is hard to find. As explained later, the directory associated with the file fstx.dll appears to involve what Microsoft calls the transactional NTFS, which allows developers to have “transactional atomicity” for file operations in transactions with a single file, multiple files, or ones that span multiple sources.

The steps for carrying out the bypass are simple:

  1. Copy the custom FsTx folder from the Nightmare-Eclipse exploit page to an NTFS- or FAT-formatted USB drive
  2. Connect the USB drive to the BitLocker-protected device
  3. Boot up the device and immediately press and hold down the [Ctrl] key
  4. Enter Windows recovery

There are at least two ways to accomplish the third step. One way is to boot into Windows, hold down the [Shift] key, click on the power icon, and click restart. Another is to power on the device and restart it as soon as Windows starts booting.

In either case, a command (CMD.EXE) prompt appears. The prompt has full access to the entire drive contents, allowing an attacker to copy, modify, or delete them. In a normal Windows Recovery flow, the attacker would need to enter a BitLocker recovery key. Somehow, the YellowKey exploit bypasses this safeguard. Multiple researchers, including Kevin Beaumont and Will Dormann, have confirmed the exploit works as described here.

It’s unclear what in the custom FsTx folder causes the bypass. Dormann said that it appears to be related to Transactional NTFS, which itself uses command-log file system under the hood. Dormann further noted that by looking at the Windows fstx.dll, one will see code that explicitly looks for \System Volume Information\FsTx in the FsTxFindSessions() function.”



Source link

  • Related Posts

    Pixel Watch 5 vs. Galaxy Watch 9: Comparing Google and Samsung’s New Watches

    While the Pixel 11 series received the spotlight at this week’s Made by Google event, the company also unveiled the Pixel Watch 5, its latest smartwatch. Though it looks similar…

    Apple trained its own AI model for China with help from Alibaba

    Apple has reportedly trained a custom AI model for the China market alongside domestic tech giant Alibaba, a rare cross-border partnership that cuts across growing tensions between Beijing and Washington.…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    BBC Sport quiz: Who am I? Guess The Hundred star cricketer No 25

    BBC Sport quiz: Who am I? Guess The Hundred star cricketer No 25

    Dump Trucks, AI, and Unemployment

    Dump Trucks, AI, and Unemployment

    New Zealand break ranks with Oceania as FIFA’s Infantino divide grows | World Cup News

    New Zealand break ranks with Oceania as FIFA’s Infantino divide grows | World Cup News

    Parrish, Crombie tied in race to become Mississauga’s next mayor, according to poll – Toronto

    Parrish, Crombie tied in race to become Mississauga’s next mayor, according to poll – Toronto

    Pixel Watch 5 vs. Galaxy Watch 9: Comparing Google and Samsung’s New Watches

    Pixel Watch 5 vs. Galaxy Watch 9: Comparing Google and Samsung’s New Watches

    Total War: Warhammer 3 is getting a big free vampiric update in September, alongside the epithet-stuffed Lords of the End Times DLC

    Total War: Warhammer 3 is getting a big free vampiric update in September, alongside the epithet-stuffed Lords of the End Times DLC