Zero-Day Exploit Against Windows BitLocker
A new zero-day exploit, dubbed YellowKey, has been discovered targeting Windows BitLocker encryption. The vulnerability allows attackers to bypass BitLocker's security measures with physical access to the affected device. This poses a significant risk to organizations utilizing BitLocker for full-disk encryption, particularly those with government contracts.
The exploit, developed by a researcher known as Nightmare-Eclipse, leverages weaknesses in Windows 11's BitLocker implementation. Specifically, YellowKey circumvents the standard security protocols by requiring physical access to the computer. This is achieved by targeting the Trusted Platform Module (TPM), the hardware component responsible for securely storing BitLocker's decryption keys. The discovery highlights the ongoing challenge of securing full-disk encryption solutions against sophisticated attacks.