#10
SecurityWeek
general
June 11, 2026 at 09:56 UTC
‘GreatXML’ Zero-Day Exploit Bypasses BitLocker
By Ionut Arghire
AI Summary
A proof-of-concept zero-day exploit dubbed 'GreatXML' bypasses Microsoft BitLocker by abusing Microsoft Defender's offline scan feature to spawn a SYSTEM-level shell when a target machine is rebooted into Recovery Mode. The technique requires physical or logical access to trigger a recovery reboot, but once triggered it fully circumvents BitLocker's disk encryption protections — a significant concern for endpoint security posture on Windows systems.
Relevance score: 75.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →