<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Giveaway of the Day Forums &#187; Topic: Possible BitLocker Zero Day Vulnerability</title>
		<link>https://www.giveawayoftheday.com/forums/topic/478111</link>
		<description>Giveaway of the Day Forums &#187; Topic: Possible BitLocker Zero Day Vulnerability</description>
		<language>en-US</language>
		<pubDate>Tue, 21 Jul 2026 09:56:41 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.2</generator>
		<atom:link href="https://www.giveawayoftheday.com/forums/rss/topic/478111" rel="self" type="application/rss+xml" />

		<item>
			<title>mikiem2 on "Possible BitLocker Zero Day Vulnerability"</title>
			<link>https://www.giveawayoftheday.com/forums/topic/478111#post-605511</link>
			<pubDate>Fri, 22 May 2026 21:53:33 +0000</pubDate>
			<dc:creator>mikiem2</dc:creator>
			<guid isPermaLink="false">605511@https://www.giveawayoftheday.com/forums/</guid>
			<description><p>msrc.microsoft[.]com/update-guide/vulnerability/CVE-2026-45585</p>
<p>Microsoft has released a script to mitigate the vulnerability by removing autofstx.exe from WinRE, the recovery environment stored on the Recovery partition.</p>
<p><blockquote>This script is an interim security fix that helps to reduce the risk of exploitation of the vulnerability.</p>
<p>The script is for WinRE and removes autofstx.exe from the BootExecute registry value. Since BootExecute runs programs very early in boot (even in recovery mode), removing this entry prevents that executable from running in a high‑privilege environment, reducing risk.</p>
<p>It works by mounting the WinRE image, editing its offline SYSTEM registry to remove the entry if present, then safely committing changes and re‑sealing WinRE so BitLocker trust remains intact.</p>
<p>It’s designed to be safe—if the autofstx.exe entry isn’t there, it exits without making changes.</blockquote>
</p></description>
		</item>
		<item>
			<title>mikiem2 on "Possible BitLocker Zero Day Vulnerability"</title>
			<link>https://www.giveawayoftheday.com/forums/topic/478111#post-605358</link>
			<pubDate>Fri, 15 May 2026 02:21:43 +0000</pubDate>
			<dc:creator>mikiem2</dc:creator>
			<guid isPermaLink="false">605358@https://www.giveawayoftheday.com/forums/</guid>
			<description><p>tomshardware[.]com/tech-industry/cyber-security/microsoft-bitlocker-protected-drives-can-now-be-opened-with-just-some-files-on-a-usb-stick-yellowkey-zero-day-exploit-demonstrates-an-apparent-backdoor</p>
<p>bleepingcomputer[.]com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/</p>
<p>I say *possible* because *to me* it does not seem it would be immediately useful to cyber criminals, though they might be able to build on it, taking the exploit further. To perform the exploit as published you copy the FsTx folder to the System Volume Information on a USB stick, cause the system to reboot into the Recovery Environment, then hold down the Control key until it reboots. When it restarts you&#39;ll be at the Command Prompt with full access to the encrypted drive. </p>
<p>Of course, if you are in the running copy of Windows, which is necessary to pull this off, you already have access to the files on the BitLocker encrypted system disk, so while I may be missing something here, what is the point?
</p></description>
		</item>

	</channel>
</rss>
