A newly disclosed “GreatXML” exploit is reported to bypass Windows BitLocker protection by leveraging files on the system’s Recovery Partition. Multiple sources describe how the exploit targets how Windows handles Recovery Mode content, specifically involving XML files located in the Recovery Partition. The researcher credited with the discovery is described as Chaotic Eclipse (also known by aliases including Nightmare-Eclipse and MSNightmare). The discovery is also linked to earlier work involving Microsoft Defender’s Offline Scan: one account says the proof of concept (PoC) uses that offline scanning process to spawn a SYSTEM shell after rebooting in Recovery Mode, which then enables the BitLocker bypass. Another source frames the bypass as occurring through the use of recovery partition XML files. The reports note that the researcher released details shortly after publishing an exploit for Microsoft Defender, describing the work as an accidental find that took a limited amount of time. Across coverage, the common theme is that GreatXML uses a chain involving Recovery Mode and Defender-related offline behavior to achieve elevated access and circumvent BitLocker, with the PoC tied to recovery partition components. The reports do not describe a specific mitigation in the provided excerpts.
GreatXML exploit bypasses Windows BitLocker using Recovery Partition XML files
A newly disclosed “GreatXML” exploit is reported to bypass Windows BitLocker protection by leveraging files on the system’s Recovery Partition. Multiple sources describe how the exploit targets how Wi...
- A “GreatXML” exploit is reported to bypass Windows BitLocker.
- The exploit uses Recovery Partition XML files and involves booting into Windows Recovery Mode.
- The PoC is described as spawning a SYSTEM shell in connection with Microsoft Defender Offline Scan behavior.
- The researcher behind the disclosure is identified as Chaotic Eclipse (with multiple aliases).
- The disclosure follows an earlier public exploit related to Microsoft Defender, released shortly before GreatXML.
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day after they published an exploit for Microsoft Defender. "This was an accidental discovery, it took a total of 4 hours to find this," the researcher said in a post on Blogger. "If you ever attempted to use Windows Defender Offline Scan, you're
2 months agoThe PoC exploits Microsoft Defender’s offline scan to spawn a SYSTEM shell when rebooting in Recovery Mode. The post ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker appeared first on SecurityWeek.
2 months ago
Android 17 QPR2 Beta 4 rolls out for Pixel phones, with Pixel 11 support pending
Google is rolling out Android 17 QPR2 Beta 4 for supported Pixel devices, following a larger Android 17 release earlier...
RFK Jr. says Pennsylvania measles deaths may be ‘fabricated,’ fueling vaccine misinformation
Two measles-associated deaths in Pennsylvania—reported to include an infant/newborn—prompt an online dispute involving U...
Wordle daily hints and answers published for multiple dates by CNET and Forbes
CNET and Forbes publish daily Wordle support that typically includes hints, the solution, and basic help for players. Th...