Microsoft Mitigates Dangerous YellowKey Tool That Breaks BitLocker

https://hothardware.com/contentimages/NewsItem/70659/content/16x9_2133x1200_highres-bitlocker.jpg

A few week back, aggrieved cybersecurity researcher Nightmare-Eclipse released a pair of Windows exploits dubbed YellowKey and GreenPlasma, following his reveal of three Windows Defender-related zero-days last month. GreenPlasma relates to an elevation of privilege vulnerability, but was released in an incomplete form that required extensive know-how to properly leverage the exploit. YellowKey exposed a glaring security hole in the Windows Recovery Environment (WinRE) that can be used to bypass BitLocker entirely, and both exploits remain unpatched.

Microsoft, however, has found a way to somewhat mitigate YellowKey, but it may require some manual tweaking from BitLocker users. Microsoft also states that it will patch the vulnerability at some point. For now though, Microsoft claims the best way to mitigate against YellowKey is to configure BitLocker to require both TPM and a PIN or to remove AutoFSTX.exe from BootExecute on WinRE. Existing BitLocker users who already have their systems secured with...

Copyright of this story solely belongs to hothardware.com. To see the full text click HERE