Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1577+ Articles
153+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Researcher Drops YellowKey, GreenPlasma Windows Zero-Days
Researcher Drops YellowKey, GreenPlasma Windows Zero-Days
NEWS

Researcher Drops YellowKey, GreenPlasma Windows Zero-Days

A security researcher has publicly released two unpatched Windows zero-day exploits: YellowKey, a BitLocker bypass requiring physical access, and...

Dylan H.

News Desk

May 14, 2026
3 min read

A security researcher has publicly dropped two previously unknown Windows zero-day exploits — dubbed YellowKey and GreenPlasma — without coordinating disclosure with Microsoft. The public release puts Windows users at immediate risk from both a drive encryption bypass and an elevation of privileges attack.

YellowKey: BitLocker Bypass

YellowKey is a BitLocker bypass exploit that allows an attacker with physical access to a Windows device to circumvent Microsoft's full-disk encryption. While the physical access requirement limits remote exploitation, the bypass is significant in scenarios involving:

  • Stolen or lost laptops
  • Physical security breaches
  • Insider threats with brief physical device access
  • Law enforcement or forensic scenarios on locked devices

BitLocker is widely used by enterprises to protect sensitive data at rest. A successful bypass could expose confidential documents, credentials, encryption keys, and other data even when the device is powered off or locked.

The technical mechanism of YellowKey takes advantage of a flaw in how BitLocker validates the pre-boot environment, potentially enabling an attacker to boot into a state where disk encryption can be bypassed or the recovery key extracted.

GreenPlasma: Elevation of Privileges to SYSTEM

GreenPlasma is a local privilege escalation (LPE) exploit that allows a low-privileged Windows user to escalate their permissions to SYSTEM — the highest privilege level on a Windows machine. This class of vulnerability is commonly chained with other exploits in real-world attacks:

  1. Attacker gains initial foothold via phishing or RCE with limited privileges
  2. GreenPlasma is deployed to escalate to SYSTEM
  3. Attacker now has full control over the compromised host

SYSTEM-level access enables an attacker to:

  • Disable antivirus and endpoint detection tools
  • Dump credential hashes from memory (LSASS)
  • Install persistent backdoors or rootkits
  • Access any file or resource on the system

Disclosure Concerns

The researcher released both exploits publicly without prior notification to Microsoft, bypassing responsible disclosure practices. This leaves Windows users unpatched and exposed until Microsoft issues an emergency fix or the next Patch Tuesday cycle.

This follows a recent pattern of so-called "full disclosure" drops where researchers frustrated with vendor response times — or seeking to demonstrate severity — release working exploit code without a coordinated patch timeline.

Microsoft has not yet acknowledged the vulnerabilities or issued an advisory as of publication.

What Windows Users Should Do

Until official patches are released:

For YellowKey (BitLocker bypass):

  • Enable pre-boot authentication with a strong PIN in addition to TPM
  • Enable Secure Boot and ensure UEFI firmware is up to date
  • Physically secure devices and monitor for unauthorized physical access
  • Consider enabling BitLocker Network Unlock policies where appropriate

For GreenPlasma (Privilege Escalation):

  • Apply Principle of Least Privilege — ensure users do not run with unnecessary administrative rights
  • Enable Windows Defender Exploit Guard and Attack Surface Reduction (ASR) rules
  • Monitor for anomalous privilege changes using Windows Event Logs (Event ID 4672, 4697)
  • Keep endpoint detection and response (EDR) tools current and active

General:

  • Watch for Microsoft security advisories and apply emergency patches as soon as they are released
  • Monitor Microsoft's Security Update Guide for out-of-band updates

References

  • SecurityWeek: Researcher Drops YellowKey, GreenPlasma Windows Zero-Days
  • Microsoft Security Response Center (MSRC)
  • Related: 2026-04-06 Windows BluehHammer Zero-Day
#Zero-Day#Windows#BitLocker#Privilege Escalation#SecurityWeek

Related Articles

Microsoft Patches YellowKey, GreenPlasma, and MiniPlasma Zero-Days

Microsoft's June 2026 Patch Tuesday fixes three actively exploited Windows zero-days: two SYSTEM privilege escalation flaws and a BitLocker bypass...

4 min read

Windows Zero-Days Expose BitLocker Bypasses and CTFMON

An anonymous researcher has publicly disclosed two new unpatched Windows zero-days — YellowKey enabling BitLocker bypass and GreenPlasma targeting CTFMON...

6 min read

Windows BitLocker Zero-Day Gives Access to Protected

A cybersecurity researcher has published proof-of-concept exploits for two unpatched Windows vulnerabilities — YellowKey (BitLocker bypass) and...

7 min read
Back to all News