Friday, September 11, 2026

GreatXML Zero-Day Enables BitLocker Bypass Through Windows Defender Offline Scan

A newly disclosed zero-day vulnerability dubbed “GreatXML” is raising serious concerns across the Windows security ecosystem, as it enables a practical BitLocker bypass by abusing the Windows Defender Offline Scan mechanism and Windows Recovery Environment (WinRE).

The issue, published by a researcher known as “MSNightmare” (Nightmare Eclipse), demonstrates how systems that have previously initiated a Defender Offline Scan can be left in a persistently weakened state, allowing attackers with physical access to gain unrestricted access to encrypted volumes without authentication.

GreatXML Zero-Day Enables BitLocker Bypass

According to the publicly released proof-of-concept (PoC) and accompanying repository, the vulnerability hinges on how Windows handles recovery boot configurations and unattended setup files during offline scanning scenarios.

Specifically, attackers can place a crafted “unattend.xml” file alongside a modified Recovery directory at the root of the system’s recovery partition.

By forcing the system to boot into WinRE, typically achieved via a Shift + Restart sequence, the environment processes the malicious configuration. It spawns a privileged shell with direct access to the BitLocker-protected volume.

machine is automatically vulnerable (Source: Github)
machine is automatically vulnerable (Source: Github)

The most concerning aspect of the GreatXML flaw is its persistence condition. The researcher claims that any system that has ever executed a Windows Defender Offline Scan becomes inherently vulnerable, even if the scan occurred in the past.

This suggests that artifacts or configuration changes introduced during the offline scan process are not properly secured or cleaned up, effectively weakening the trust boundary between the recovery environment and the encrypted OS volume.

Source: Github
Source: Github

In scenarios where the feature has not been used, attackers may still be able to trigger the vulnerable state by initiating or simulating an offline scan, although this vector remains less well-defined.

From a technical standpoint, the attack bypasses BitLocker’s intended protection model by exploiting trust assumptions in pre-boot and recovery workflows rather than cryptographic weaknesses.

BitLocker is designed to protect data at rest, particularly against offline attacks; however, if an attacker can execute arbitrary code within WinRE with elevated privileges and access to mounted volumes, the encryption becomes effectively moot.

This aligns with a broader class of attacks targeting pre-boot environments, where security controls are often less rigorously enforced.

The disclosure has not yet been accompanied by an official CVE identifier or vendor advisory at the time of writing, and Microsoft has not publicly acknowledged the issue.

Given the low complexity and reproducibility described in the PoC, the vulnerability poses a credible risk in scenarios involving lost or stolen devices, shared physical access environments, or forensic bypass attempts.

Security practitioners are advised to monitor Microsoft updates and consider interim mitigations, such as restricting physical access, disabling or auditing WinRE usage, and reviewing policies for Defender Offline Scan deployment.

Additionally, organizations relying heavily on BitLocker for endpoint protection should reassess their threat models to account for pre-boot and recovery environment abuse cases, which continue to emerge as a critical attack surface.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News