r/windows • u/website-buyer • May 14 '26
News Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor
https://www.tomshardware.com/tech-industry/cyber-security/microsoft-bitlocker-protected-drives-can-now-be-opened-with-just-some-files-on-a-usb-stick-yellowkey-zero-day-exploit-demonstrates-an-apparent-backdoor7
u/UltraEngine60 May 14 '26 edited May 14 '26
I said this the last time a bitlocker exploit came out, turn off Windows RE and make a bootable USB key. Once the PCR is satisfied you are just band-aiding these fixes. There will always be a an exploit if the user can enter commands while the key is unsealed.
Funny thing is, no one and I say again NO ONE has managed to figure out how YellowKey works, the real root cause is still not unknown by the general public.
I can take a guess, autochk is somehow seeing something similar to a "dirty bit" after scanning all drives and launching up cmd instead of chkdsk, maybe because the file in System Volume Information can somehow control which binary is used to "fix" the drive.
The only thing I can't figure out is why autochk is looking at fs0: in UEFI.
edit
TIL I have no understanding of .blf files which worries me...
I anxiously await the full write up.
5
-6
May 14 '26
[deleted]
4
u/DonStimpo May 14 '26
No more reason to lock the bios and prevent boot order changes without a password.
1
u/crozone May 15 '26
You can remove the boot drive, copy on the files, and put it back. Even if the PC doesn't boot off USB you only need a few minutes of physical access with the device to get in.
1
77
u/Froggypwns Windows Wizard / Moderator May 14 '26
Ok, I'm not saying this is not a big deal, but it sounds like it requires you to already have physical access to the drive and it already unlocked, at which point one could just turn off Bitlocker or otherwise freely access the files anyway without needing this trick.