A newly disclosed zero-day vulnerability dubbed “GreatXML” is raising serious concerns across the Windows security ecosystem, as it enables a practical BitLocker bypass by abusing the Windows Defender Offline Scan mechanism and Windows Recovery Environment (WinRE).
The issue, published by a researcher known as “MSNightmare” (Nightmare Eclipse), demonstrates how systems that have previously initiated a Defender Offline Scan can be left in a persistently weakened state, allowing attackers with physical access to gain unrestricted access to encrypted volumes without authentication.
GreatXML Zero-Day Enables BitLocker Bypass
According to the publicly released proof-of-concept (PoC) and accompanying repository, the vulnerability hinges on how Windows handles recovery boot configurations and unattended setup files during offline scanning scenarios.
Specifically, attackers can place a crafted “unattend.xml” file alongside a modified Recovery directory at the root of the system’s recovery partition.
By forcing the system to boot into WinRE, typically achieved via a Shift + Restart sequence, the environment processes the malicious configuration. It spawns a privileged shell with direct access to the BitLocker-protected volume.

The most concerning aspect of the GreatXML flaw is its persistence condition. The researcher claims that any system that has ever executed a Windows Defender Offline Scan becomes inherently vulnerable, even if the scan occurred in the past.
This suggests that artifacts or configuration changes introduced during the offline scan process are not properly secured or cleaned up, effectively weakening the trust boundary between the recovery environment and the encrypted OS volume.

In scenarios where the feature has not been used, attackers may still be able to trigger the vulnerable state by initiating or simulating an offline scan, although this vector remains less well-defined.
From a technical standpoint, the attack bypasses BitLocker’s intended protection model by exploiting trust assumptions in pre-boot and recovery workflows rather than cryptographic weaknesses.
BitLocker is designed to protect data at rest, particularly against offline attacks; however, if an attacker can execute arbitrary code within WinRE with elevated privileges and access to mounted volumes, the encryption becomes effectively moot.
This aligns with a broader class of attacks targeting pre-boot environments, where security controls are often less rigorously enforced.
The disclosure has not yet been accompanied by an official CVE identifier or vendor advisory at the time of writing, and Microsoft has not publicly acknowledged the issue.
Given the low complexity and reproducibility described in the PoC, the vulnerability poses a credible risk in scenarios involving lost or stolen devices, shared physical access environments, or forensic bypass attempts.
Security practitioners are advised to monitor Microsoft updates and consider interim mitigations, such as restricting physical access, disabling or auditing WinRE usage, and reviewing policies for Defender Offline Scan deployment.
Additionally, organizations relying heavily on BitLocker for endpoint protection should reassess their threat models to account for pre-boot and recovery environment abuse cases, which continue to emerge as a critical attack surface.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





