Particle.news
Download on the App Store

Researcher’s Exploits Revive MiniPlasma Bug and Flag BitLocker Bypass in Windows

Independent tests raise pressure on Microsoft to issue a formal fix.

Overview

  • An anonymous researcher released working code that reactivates the MiniPlasma vulnerability and introduced a new BitLocker bypass dubbed YellowKey.
  • MiniPlasma still lets a standard Windows account gain SYSTEM privileges by abusing the Cloud Files driver cldflt.sys on fully patched Windows 11.
  • BleepingComputer and security analyst Will Dormann reproduced the MiniPlasma exploit, while a recent Windows 11 Insider build did not show the issue, suggesting a fix is near.
  • YellowKey reportedly unlocks BitLocker‑protected drives with local access by using a USB that holds a \System Volume Information\FsTx folder and booting into the Windows Recovery Environment; Windows 10’s recovery is not affected.
  • Dormann reported that YellowKey’s behavior differs from the published steps and its mechanism remains unclear, and Microsoft said it is investigating reported issues under coordinated disclosure.