Public 'GreatXML' zero-day lets attackers bypass BitLocker on Windows after Microsoft Defender Offline scan is used

A newly published Windows exploit can unlock some BitLocker-protected PCs and open a SYSTEM-level command prompt in Recovery Mode. Security researcher Nightmare Eclipse says the 'GreatXML' proof of concept abuses Microsoft Defender Offline scan behavior rather than a published CVE; systems become vulnerable after Defender Offline scan has been initiated at least once, and the attack involves placing crafted XML files in the recovery partition and booting into Windows Recovery Environment (WinRE).
Why it matters: This weakens one of Windows' main disk-encryption protections for affected machines, especially if an attacker can get local access or trigger the precondition. Windows defenders should watch for Microsoft guidance, restrict unauthorized physical and admin access, and review whether Defender Offline scan can be abused in their environment.

Sources

Microsoft's worst 'Nightmare' unleashes BitLocker bypass 0-day
2026.06.11 98% relevant
This article is directly about the same GreatXML BitLocker-bypass zero-day, adding reporting that the exploit was published on GitHub, Microsoft had not yet responded on GreatXML, and Will Dormann questioned the practical impact because reproducing it appears to require an admin-triggered Defender Offline scan.
New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
info@thehackernews.com (The Hacker News) 2026.06.11 98% relevant
This is the same underlying event: the newly disclosed GreatXML exploit that abuses Windows recovery-partition XML files to bypass BitLocker protections and gain access on affected Windows systems.
‘GreatXML’ Zero-Day Exploit Bypasses BitLocker
Ionut Arghire 2026.06.11 100% relevant
This article establishes a distinct new zero-day event: a separate Nightmare Eclipse disclosure named GreatXML that bypasses BitLocker via Microsoft Defender Offline scan and WinRE, not the previously tracked YellowKey or RoguePlanet flaws.
← Back to all stories