GreatXML Bypass Unlocks BitLocker via WinRE XML Files

TL;DR Summary
Security researcher Chaotic Eclipse unveiled GreatXML, a new Windows BitLocker bypass that places crafted unattend.xml and Recovery/WindowsRE/ReAgent.xml on the recovery partition and, after rebooting into WinRE, spawns a shell with unrestricted access to the BitLocker volume. It builds on a recent Defender-related exploit and is the second BitLocker bypass from the researcher, with Microsoft having patched a prior bypass (YellowKey CVE-2026-45585) this Patch Tuesday.
- New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files The Hacker News
- Microsoft's worst 'Nightmare' unleashes BitLocker bypass 0-day The Register
- Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research Security Affairs
- Windows BitLocker 0-Day Vulnerability Allows Attackers to Bypass Security Feature CyberSecurityNews
- GreatXML Zero-Day Enables BitLocker Bypass Through Windows Defender Offline Scan gbhackers.com
Reading Insights
Total Reads
0
Unique Readers
32
Time Saved
1 min
vs 2 min read
Condensed
78%
285 → 64 words
Want the full story? Read the original article
Read on The Hacker News