YellowKey reportedly works in Windows 11, Windows Server 2022 and 2025, but not in Windows 10.

  • Cornballer@lemmy.zip
    link
    fedilink
    English
    arrow-up
    11
    ·
    edit-2
    2 hours ago

    Somebody on twitter “reverse engineered” the exploit. Apparently ms shipped debug code in production. At least it’s not called Backdoor_FBI outright.

    How it works:

    1. Recovery tools look for a config file called RecoverySimulation.ini on the OS drive
    2. If Active=Yes, it enables “test mode” for the recovery tools
    3. Test mode unlocks your BitLocker drive but a flag called FailRelock tells it to skip relocking
    4. cmd.exe spawns with full access to your “encrypted” drive