#7
The Hacker News
general
June 11, 2026 at 17:43 UTC
New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
By [email protected] (The Hacker News)
AI Summary
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse/MSNightmare) released GreatXML, a Windows BitLocker bypass that exploits malicious XML files in the recovery partition via Microsoft Defender's offline scan feature to spawn a SYSTEM shell during Recovery Mode reboot — reportedly discovered accidentally in 4 hours. This follows the researcher's separate release of RoguePlanet, a Windows Defender local privilege escalation exploit abusing a race condition, indicating an ongoing campaign of uncoordinated vulnerability disclosure against Microsoft products.
Relevance score: 80.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →