A cybersecurity researcher has disclosed two additional unpatched Microsoft Windows zero-day vulnerabilities affecting BitLocker and local privileges. The flaws are codenamed YellowKey and GreenPlasma. YellowKey is described as a BitLocker bypass that can grant access to drives protected by default Windows BitLocker configurations. Multiple reports say the published proof-of-concept details require physical access to the affected device and involve loading provided exploit files from a USB drive and completing a key sequence to obtain unrestricted shell access on a BitLocker-protected machine. Bruce Schneier’s account emphasizes that BitLocker typically uses a TPM to store the decryption key and that bypassing it undermines protection on stolen devices.

In parallel, GreenPlasma is presented as a privilege-escalation issue impacting the Windows Collaborative Translation Framework (CTFMON). Sources report partial exploit code was released rather than a complete proof of concept, and that in default configurations it appears to trigger a UAC consent prompt.

Microsoft has shared mitigations for YellowKey, and security researchers quoted in coverage also discuss potential mitigations such as enabling a BitLocker PIN and adding BIOS password lock. Reports indicate no confirmed mitigation for GreenPlasma beyond patching once Microsoft addresses it.