Overview
- An anonymous researcher released working code that reactivates the MiniPlasma vulnerability and introduced a new BitLocker bypass dubbed YellowKey.
- MiniPlasma still lets a standard Windows account gain SYSTEM privileges by abusing the Cloud Files driver cldflt.sys on fully patched Windows 11.
- BleepingComputer and security analyst Will Dormann reproduced the MiniPlasma exploit, while a recent Windows 11 Insider build did not show the issue, suggesting a fix is near.
- YellowKey reportedly unlocks BitLocker‑protected drives with local access by using a USB that holds a \System Volume Information\FsTx folder and booting into the Windows Recovery Environment; Windows 10’s recovery is not affected.
- Dormann reported that YellowKey’s behavior differs from the published steps and its mechanism remains unclear, and Microsoft said it is investigating reported issues under coordinated disclosure.