# YellowKey & GreenPlasma — Unpatched Windows BitLocker Bypass & CTFMON LPE Zero-Days With Public PoC (Chaotic/Nightmare Eclipse)

> On May 13, 2026, the researcher Chaotic Eclipse (GitHub: Nightmare-Eclipse) published two unpatched Windows zero-day exploits as a protest against Microsoft's vulnerability handling. YellowKey is a BitLocker bypass affecting Windows 11 and Windows Server 2022/2025 that abuses Windows Recovery Environment (WinRE) NTFS transaction-log replay to delete X:\Windows\System32\winpeshl.ini, causing WinRE to launch cmd.exe with full read/write access to the still-unlocked BitLocker volume. GreenPlasma is a Local Privilege Escalation flaw ("Windows CTFMON Arbitrary Section Creation EoP") in which an unprivileged user creates arbitrary memory-section objects inside SYSTEM-writable directory objects, enabling manipulation of privileged services to obtain a SYSTEM shell. Kevin Beaumont independently validated YellowKey; Will Dormann (Analygence) reproduced the USB variant and identified the NTFS log-replay root cause. TPM-only and TPM+PIN BitLocker configurations are both bypassable. No CVEs are assigned and no Microsoft patch exists.

- **Published:** 2026-05-13T12:00:00Z
- **Last reviewed:** 2026-05-13T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0512
- **ID:** TL-2026-0512
- **Severity:** CRITICAL (CVSS 9.3)
- **Category:** ZERO_DAY
- **Status:** ACTIVE
- **Actor:** Chaotic Eclipse
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

OVERVIEW
On May 13, 2026, the security researcher who self-identifies as "Chaotic Eclipse" (GitHub handle Nightmare-Eclipse) publicly released proof-of-concept exploit code for two unpatched Microsoft Windows zero-day vulnerabilities — YellowKey, a BitLocker authentication/encryption bypass, and GreenPlasma, a kernel-assisted local privilege escalation. The disclosure was performed without coordinated vulnerability disclosure (CVD); the researcher cites dissatisfaction with Microsoft's bug-handling and has publicly promised to leak additional Windows exploits, including "a big surprise" for the next Patch Tuesday. The repository (github.com/Nightmare-Eclipse/YellowKey) reached 999 stars and 225 forks within hours of publication.

The disclosure follows the same actor's prior releases: BlueHammer (CVE-2026-33825, Microsoft Defender LPE via TOCTOU on the file-remediation engine, patched April 2026), RedSun (a sibling Defender LPE that was silently patched), and UnDefend. Huntress Labs (May 2026) reported all three of those prior PoCs were observed in real-world intrusions within weeks of disclosure, making operational weaponization of YellowKey and GreenPlasma highly probable.

YELLOWKEY — TECHNICAL ANALYSIS (BITLOCKER BYPASS)
YellowKey exploits a logic flaw in the Windows Recovery Environment (WinRE) boot image that is not present in the equivalent components of the mainline OS install — the researcher and several independent reviewers (Will Dormann/Analygence, Kevin Beaumont) note that the same code in normal Windows lacks the exploitable behavior, leading the researcher to credit, sarcastically, "MORSE, MSTIC, and Microsoft GHOST" and to describe the component as an apparent backdoor.

Root cause (per Will Dormann's reproduction): WinRE, on boot, enumerates attached volumes and replays NTFS Transactional Resource Manager (TxR) logs found in each volume's "\System Volume Information\FsTx\<GUID>\" directory. The exploit ships a precrafted FsTx directory (GUID 95F62703B343F111A92A005056975458) containing FsTxLogs/ and FsTxTemp/ subdirectories whose log records, when replayed, cause WinRE's RAM disk image (X:\) to drop or overwrite X:\Windows\System32\winpeshl.ini. Because winpeshl.ini specifies the recovery interface to launch, its absence causes WinRE to fall back to launching cmd.exe — and crucially, by this point WinRE has already invoked the TPM-sealed VMK and mounted the BitLocker volume read/write at C:\. The attacker is dropped into an unrestricted SYSTEM command prompt with full access to the plaintext BitLocker volume — no recovery key, no PIN, no unlock prompt.

Exploitation procedure (USB variant):
1. Attacker formats a FAT32/NTFS USB stick.
2. Copies the YellowKey FsTx folder verbatim to <USB>:\System Volume Information\FsTx\95F62703B343F111A92A005056975458\.
3. Inserts USB into the target machine (powered on at the lock screen, or off).
4. Holds Shift and clicks Restart -> Troubleshoot -> Advanced -> WinRE.
5. Releases Shift on click; immediately holds CTRL and keeps holding it through reboot.
6. If timing aligns, WinRE drops to a cmd.exe shell with the BitLocker C:\ volume mounted.

Exploitation procedure (EFI variant — bypasses "no removable media" GPO):
1. Attacker removes the disk from the target machine.
2. Mounts the EFI System Partition on a controlled workstation.
3. Writes the FsTx folder to the EFI partition (path not publicly disclosed in full).
4. Re-installs the disk and boots normally; WinRE replay path is hit during the next recovery cycle.
Will Dormann reproduced the USB variant but did not reproduce the EFI variant in his testbed.

TPM+PIN: Chaotic Eclipse states the exploit "still works in TPM+PIN environments" but withheld the TPM+PIN trigger variant. The disclosed USB/EFI variant is reported to work against TPM-only configurations, which are the Windows 11 default.

GREENPLASMA — TECHNICAL ANALYSIS (CTFMON ARBITRARY SECTION CREATION LPE)
GreenPlasma is described by the researcher as a "Windows CTFMON Arbitrary Section Creation Elevation of Privileges Vulnerability." The underlying primitive: an unprivileged user can create kernel section objects (Section, \KnownDlls-style mapped memory) inside directory objects in the NT object namespace that are writable by SYSTEM but should not be writable (or attacker-controllable) from a Medium IL token. ctfmon.exe (and other SYSTEM services that resolve handles by name in the object namespace) then opens the attacker-planted section, mapping attacker-controlled memory into a privileged context. A complete exploit chains the section-creation primitive to hijack a SYSTEM service's code or data path, producing a SYSTEM shell.

The published PoC is intentionally incomplete — the final "smart-enough" pivot to a full SYSTEM shell is withheld but is described as straightforward for capable attackers. Independent SOC telemetry (Huntress) has historically observed Nightmare-Eclipse PoCs operationalized within days of release; defenders should assume a full chain is in private circulation.

IMPACT
YellowKey collapses the trust boundary that Windows full-disk encryption is designed to enforce. Any attacker with brief physical access to a Windows 11 or Server 2022/2025 endpoint can read, modify, or implant on the entire encrypted volume — extracting Active Directory credentials (SAM, NTDS.DIT on DCs), browser/credential vaults (DPAPI material), Outlook OST, source code, certificate stores — without ever seeing a recovery-key or PIN prompt. The "evil maid" threat model that BitLocker was specifically designed to resist is fully realized. Combined with GreenPlasma, an attacker who lands on the box with any user-level foothold then has a reliable path to SYSTEM, completing local compromise.

MITIGATIONS (No vendor patch as of 2026-05-13)
- Enforce Pre-Boot authentication (TPM+PIN+USB key, or BitLocker network unlock with strict policy) — note: researcher states TPM+PIN is also bypassable; treat as defense-in-depth only.
- Block USB mass-storage at the boot/firmware level via UEFI Secure Boot DBX, vendor BIOS USB lockdown, or physical port disable for high-value endpoints.
- Disable WinRE on production endpoints where not required: reagentc /disable; bcdedit /set {default} recoveryenabled No; remove or replace the recovery partition. Document that this also disables push-button reset/repair.
- Enable VBS/HVCI and Credential Guard so post-bypass SAM/LSA secret extraction is degraded.
- Monitor for unauthorized boots into WinRE (Event ID 7036/7045, BCD writes, recoveryenabled toggles).
- Hunt for the FsTx GUID 95F62703B343F111A92A005056975458 on attached volumes and EFI partitions.
- For GreenPlasma: enforce restricted user-mode handle access on \BaseNamedObjects and \Sessions\<id>\BaseNamedObjects; deploy EDR detections for kernel section objects opened by ctfmon.exe and other SYSTEM IME components from unexpected paths.

ATTRIBUTION & DISCLOSURE POSTURE
The researcher "Chaotic Eclipse / Nightmare-Eclipse" is positioned as a hacktivist disclosing for protest, not a financially motivated criminal actor. However, the threat-actor concern is not the researcher — it is downstream weaponization: Huntress confirmed BlueHammer/RedSun/UnDefend were operationalized within weeks. Defenders should plan for in-the-wild exploitation of YellowKey and GreenPlasma within the same horizon.

## MITRE ATT&CK

- T1091 Replication Through Removable Media
- T1200 Hardware Additions
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1542 Pre-OS Boot
- T1068 Exploitation for Privilege Escalation
- T1548 Abuse Elevation Control Mechanism
- T1006 Direct Volume Access
- T1070 Indicator Removal
- T1556 Modify Authentication Process
- T1601 Modify System Image
- T1003 OS Credential Dumping
- T1552 Unsecured Credentials
- T1083 File and Directory Discovery
- T1082 System Information Discovery
- T1005 Data from Local System
- T1560 Archive Collected Data
- T1565 Data Manipulation
- T1490 Inhibit System Recovery

## Sources

- [Windows BitLocker zero-day gives access to protected drives, PoC released](https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/)
- [Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days](https://securityonline.info/windows-bitlocker-bypass-yellowkey-greenplasma-poc-disclosure/)
- [Disgruntled researcher releases two more Microsoft zero-days](https://www.theregister.com/security/2026/05/13/disgruntled-researcher-releases-two-more-microsoft-zero-days/)
- [Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor](https://www.tomshardware.com/tech-industry/cyber-security/microsoft-bitlocker-protected-drives-can-now-be-opened-with-just-some-files-on-a-usb-stick-yellowkey-zero-day-exploit-demonstrates-an-apparent-backdoor)
- [YellowKey BitLocker Bypass Vulnerability — Nightmare-Eclipse GitHub repository](https://github.com/Nightmare-Eclipse/YellowKey)
- [YellowKey FsTx directory artifact (GUID 95F62703B343F111A92A005056975458)](https://github.com/Nightmare-Eclipse/YellowKey/tree/main/FsTx/95F62703B343F111A92A005056975458)
- [A new Windows 11 BitLocker bypass only needs a USB stick, and the researcher thinks it's a backdoor](https://www.xda-developers.com/new-windows-11-bitlocker-bypass-needs-usb-stick-researcher-backdoor/)
- [YellowKey Turns BitLocker Into an Open Door](https://www.emsi.me/tech/security/yellowkey-turns-bitlocker-into-an-open-door/2026-05-13/223a38)
- [Disgruntled researcher strikes Microsoft again: drops BitLocker bypass and privilege escalation zero-days](https://cybernews.com/security/researcher-releases-bitlocker-bypass-and-privilege-escalation-exploit/)
- [Breaking Down GreenPlasma and YellowKey: Windows Trust Boundaries Doing Windows Things](https://hetmehta.com/posts/breaking-greenplasma-yellowkey/)
- [BlueHammer & RedSun: Windows Defender CVE-2026-33825 Zero-day Vulnerability Explained](https://www.picussecurity.com/resource/blog/bluehammer-redsun-windows-defender-cve-2026-33825-zero-day-vulnerability-explained)
- [Nightmare-Eclipse Tooling Seen in Real-World Intrusion](https://www.huntress.com/blog/nightmare-eclipse-intrusion)
- [BlueHammer: Windows zero-day exploit leaked](https://www.helpnetsecurity.com/2026/04/08/bluehammer-windows-zero-day-exploit-leaked/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0512
