NOW LET US – AI RAG SaaS Studio TP.HCM
NOW LET US
Digital Product Studio
Back to news
CYBERSECURITY...1 min read

New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files

Share
NOW LET US Article – New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files

Security researcher Chaotic Eclipse has disclosed a new Windows BitLocker bypass exploit named GreatXML. While the researcher claims it leverages recovery partition XML files, other experts have raised doubts about its practical feasibility.

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day after they published an exploit for Microsoft Defender.

"This was an accidental discovery, it took a total of 4 hours to find this," the researcher said in a post on Blogger. "If you ever attempted to use Windows Defender Offline Scan, you're automatically vulnerable to a BitLocker bypass. I'm unsure if you can still trigger the bug without ever using the offline scan feature, because you can definitely."

The exploit works as follows -

  • Copy an XML file ("unattend.xml") and a recovery folder containing another XML file ("Recovery/WindowsRE/ReAgent.xml") to the root of the recovery partition.
  • Reboot to Windows Recovery Environment (WinRE) by holding Shift while clicking Restart in the Windows power menu.

If every step is followed correctly, the result is a shell spawned with unrestricted access to the BitLocker volume.

"If Defender offline scan was never initiated then you have to either login and initiate it yourself or figure out a way to boot into WinRE in offline scan state (I believe it should be very possible to do so without logging in) and follow steps above," Chaotic Eclipse noted.

In a post on Mastodon, security researcher Will Dormann opined the steps to reproduce GreatXML as "flawed," adding triggering a Microsoft Defender Offline Scan requires a user to be both logged in to Windows and have admin credentials, at which point it's trivial to turn off BitLocker anyway.

"The writeup for GreatXML suggests that the prerequisite is that Windows Defender Offline has been executed at some point in the past," Dorman added. "And that after planting two files in WinRE, all you need to do is [Shift]-reboot into WinRE, and Windows will automatically go into Microsoft Defender Offline scan mode. But this is not the case in any of the 3 lineages of Win11 that I have handy."

The release of GreatXML comes not long after RoguePlanet, a zero-day flaw in Microsoft Defender that facilitates local privilege escalation (LPE) to SYSTEM, granting the attacker the ability to run arbitrary code or perform unauthorized actions.

GreatXML is also the second BitLocker bypass released by Chaotic Eclipse after YellowKey (aka CVE-2026-45585), patches for which were released by Microsoft this week as part of Patch Tuesday updates.

© 2026 Now Let Us. All rights reserved.

Source: The Hacker News

Advertisement
Ad slot ready: 5887729102

More in this category

NOW LET US Related – Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

cybersecurity

Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

Attackers hijacked over 400 Arch User Repository (AUR) packages to distribute a Rust-based credential stealer and an eBPF rootkit. Users who installed or updated AUR packages on or after June 11 are advised to audit their systems immediately.

NOW LET US Related – LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

cybersecurity

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution.

NOW LET US Related – Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs

cybersecurity

Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs

Europol and international law enforcement have disrupted AudiA6, a major cryptocurrency laundering service that washed over $389 million in illicit profits for ransomware gangs and cybercriminals.

NOW LET US Related – ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

cybersecurity

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest.

NOW LET US Related – The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

cybersecurity

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

A new analysis of The Gentlemen ransomware operation reveals its transition into an independent, AI-driven threat group capable of self-propagating like a worm and claiming hundreds of victims worldwide.

NOW LET US Related – AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.

cybersecurity

AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.

AI has compressed the time-to-exploit window from months to hours, rendering traditional vulnerability management obsolete and driving CISOs to reallocate budgets toward Breach and Attack Simulation (BAS).

EXPLORE TOPICS

Discover All Categories

Deep dive into the specific technology sectors that matter most to you.