A recently identified zero-day vulnerability poses a significant threat to Windows 11 users by enabling individuals with physical access to bypass the built-in BitLocker encryption. This exploit, referred to as YellowKey, was disclosed by a researcher known as Nightmare-Eclipse. It effectively circumvents the default BitLocker protections, which are designed to secure data by requiring a decryption key stored in a trusted platform module (TPM). BitLocker is crucial for many organizations, particularly those working with sensitive governmental data. The exploit leverages a specially crafted FsTx folder, which is not well-documented online. The folder's association with the fstx.dll file suggests a connection to Microsoft's transactional NTFS, a feature that allows for atomic file operations across various transactions. This vulnerability raises serious concerns about the integrity of data protection measures in Windows 11.
New Zero-Day Vulnerability Compromises Windows 11 BitLocker Security
A newly discovered zero-day vulnerability allows unauthorized access to encrypted drives on Windows 11 systems.
