Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1451+ Articles
151+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Microsoft Patches YellowKey, GreenPlasma, and MiniPlasma Zero-Days
Microsoft Patches YellowKey, GreenPlasma, and MiniPlasma Zero-Days
NEWS

Microsoft Patches YellowKey, GreenPlasma, and MiniPlasma Zero-Days

Microsoft's June 2026 Patch Tuesday fixes three actively exploited Windows zero-days: two SYSTEM privilege escalation flaws and a BitLocker bypass...

Dylan H.

News Desk

June 10, 2026
4 min read

Microsoft's June 2026 Patch Tuesday includes fixes for three actively exploited Windows zero-day vulnerabilities — publicly named YellowKey, GreenPlasma, and MiniPlasma — that allow attackers to gain SYSTEM-level privileges on fully patched Windows systems or bypass BitLocker drive protection.

The Three Zero-Days

YellowKey — SYSTEM Privilege Escalation

YellowKey is a local privilege escalation vulnerability in the Windows kernel. An authenticated attacker who exploits this flaw can elevate their privileges to SYSTEM level on a fully patched Windows system. The vulnerability was initially disclosed by a security researcher in May 2026 as part of a series of Windows zero-day drops following a dispute between Microsoft and the research community over disclosure practices.

Microsoft had previously come under fire for threatening legal action against researchers publishing zero-days, which some in the community argued led to coordinated disclosure of stockpiled vulnerabilities in retaliation.

GreenPlasma — SYSTEM Privilege Escalation

GreenPlasma is a second local privilege escalation zero-day, distinct from YellowKey and exploiting a different Windows component. Like YellowKey, it grants SYSTEM privileges to an authenticated attacker on a fully patched Windows machine. Both YellowKey and GreenPlasma were disclosed publicly via proof-of-concept code before patches were available.

Both flaws were flagged as actively exploited in the wild by the time Microsoft released patches, indicating threat actors had already operationalized them.

MiniPlasma — BitLocker Bypass

MiniPlasma targets BitLocker, Windows' built-in drive encryption system. The flaw allows an attacker with physical or remote access to retrieve or bypass BitLocker protection — potentially enabling access to encrypted drives without the correct credentials. This vulnerability is particularly concerning for enterprises relying on BitLocker for data-at-rest protection on laptops and workstations.

The MiniPlasma vulnerability had been under limited active exploitation, primarily by sophisticated threat actors targeting high-value targets.

Patch Tuesday June 2026 Scope

June 2026's Patch Tuesday is notably large, addressing 206 vulnerabilities in total — a record-setting monthly batch. In addition to the three zero-days, fixes include:

  • Critical Remote Code Execution vulnerabilities in Windows network components
  • Multiple Elevation of Privilege fixes across Windows services
  • Security updates for Microsoft Office, Edge, and Azure services

Why These Zero-Days Matter

The combination of YellowKey, GreenPlasma, and MiniPlasma represents a potent attack chain. An attacker who gains initial access to a Windows system — through phishing, a web exploit, or supply chain compromise — can:

  1. Use YellowKey or GreenPlasma to escalate to SYSTEM privileges
  2. Leverage SYSTEM access to extract credentials, deploy ransomware, or establish persistence
  3. If BitLocker is in use, deploy MiniPlasma to access encrypted drives

This chain works even on fully patched Windows systems (prior to the June 2026 patches), meaning organizations running current Windows updates were still vulnerable.

Recommended Actions

  1. Apply the June 2026 Patch Tuesday updates immediately — Microsoft has released patches for all three zero-days
  2. Prioritize endpoint updates — YellowKey and GreenPlasma are particularly high-risk for environments where attackers may already have local access
  3. Review BitLocker configurations — Organizations relying on BitLocker for sensitive data protection should treat MiniPlasma as high-urgency
  4. Monitor EDR telemetry — Look for privilege escalation attempts or unexpected SYSTEM-level process creation
  5. Check CISA KEV — Verify whether these vulnerabilities have been added to CISA's Known Exploited Vulnerabilities catalog for federal compliance deadlines

Context: The Researcher Disclosure Dispute

The release of YellowKey and GreenPlasma before patches were available stems from a broader dispute between Microsoft and the security research community. After Microsoft's legal threat against researchers publishing zero-days in May 2026, several researchers responded by publicly releasing vulnerability details and proof-of-concept code without waiting for patches. Microsoft has since reversed course, stating it "will not pursue security researchers" — but the damage was done, and multiple Windows zero-days were already in the public domain.

This episode underscores the critical importance of healthy vulnerability disclosure ecosystems and the real-world consequences when that trust breaks down.

#Microsoft#Zero-Day#Windows#Patch Tuesday#Privilege Escalation#BitLocker

Related Articles

Windows Zero-Days Expose BitLocker Bypasses and CTFMON

An anonymous researcher has publicly disclosed two new unpatched Windows zero-days — YellowKey enabling BitLocker bypass and GreenPlasma targeting CTFMON...

6 min read

Windows BitLocker Zero-Day Gives Access to Protected

A cybersecurity researcher has published proof-of-concept exploits for two unpatched Windows vulnerabilities — YellowKey (BitLocker bypass) and...

7 min read

Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows

Anonymous researcher Chaotic Eclipse released a PoC exploit for a new Microsoft Defender zero-day named RoguePlanet. The race condition flaw grants SYSTEM...

5 min read
Back to all News