Zero-day exploit completely defeats default Windows 11 BitLocker protections
It's not entirely clear how the exploit works. Microsoft says it's investigating.
Signal weather
Rising
Momentum is building quickly, so this card is a good early entry point into the topic.
A zero-day exploit circulating online allows people with physical access to a Windows 11 system to bypass default BitLocker protections and gain complete access to an encrypted drive within seconds. The exploit, named YellowKey, was published earlier this week by a researcher who goes by the alias Nightmare-Eclipse. It reliably bypasses default Windows 11 deployments of BitLocker, the full-volume encryption protection Microsoft provides to make disk contents off-limits to anyone without the decryption key, which is stored in a secured piece of hardware known as a trusted platform module (TPM). BitLocker is a mandatory protection for many organizations, including those that contract with governments. When one disk volume manipulates another The core of the YellowKey exploit is a custom-made FsTx folder. Online documentation of this folder is hard to find. As explained later, the directory associated with the file fstx.dll appears to involve what Microsoft calls the transactional NTFS, which allows developers to have “transactional atomicity" for file operations in transactions with a single file, multiple files, or ones that span multiple sources. Read full article Comments
Stay on the signal
Follow Zero-day exploit completely defeats default Windows 11 BitLocker protections
Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.
Story map
Understand this topic fast
A quick entry into the story: why it matters now, who is involved, and where to go next for context.
Why it matters now
Topic constellation
Open the live map for this story
See which entities, story threads, sources, and follow-up articles shape this story right now.
Click nodes to continue
Story timeline
Continue with this story
A short sequence of events and follow-up stories to understand the arc quickly.
How reliable this looks
Signal and trust for Ars Technica
This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.
Reliability
92
Freshness
100
Sources in storyline
1
Related articles
More stories that share tags, source, or category context.
Cell phone users can't stop incriminating themselves
People confide almost everything to their phones.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Energy supplier abandons Lake Tahoe residents to serve data centers
Town’s 49,000 California residents compete with Nevada data centers for energy.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Over a year later, AMD is bringing improved FSR 4 upscaling to its older GPUs
FSR 4.1 running on RDNA3 or RDNA2 GPUs may take a bigger performance hit.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Judge probes whether Musk settlement with Trump admin is tainted by corruption
Trump admin wants to let Musk pay $1.5M fine to settle $150 million Twitter suit.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
More from Ars Technica
Fresh reporting and follow-up coverage from the same newsroom.
Cell phone users can't stop incriminating themselves
People confide almost everything to their phones.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Energy supplier abandons Lake Tahoe residents to serve data centers
Town’s 49,000 California residents compete with Nevada data centers for energy.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Over a year later, AMD is bringing improved FSR 4 upscaling to its older GPUs
FSR 4.1 running on RDNA3 or RDNA2 GPUs may take a bigger performance hit.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.
Judge probes whether Musk settlement with Trump admin is tainted by corruption
Trump admin wants to let Musk pay $1.5M fine to settle $150 million Twitter suit.
Signal weather
Momentum is building quickly, so this card is a good early entry point into the topic.
Why now
Fresh coverage with immediate momentum.