Hurray, Two More Windows Zero Days To Make Your Life Better
YellowKey And GreenPlasma Laugh At Your Patch Tuesday
There is someone even more upset with Microsoft that you or I; releasing two more Windows zero days just after Patch Tuesday. YellowKey and GreenPlasma are both rather nasty, with YellowKey not only being the worst of the two but also the one that has been released in full. It is a way to break BitLocker protection, which is not great if you depend on it to protect lost laptops. It consists of a couple of files that can be loaded onto a USB drive and plugged into any laptop. A tiny bit of work and you will get unrestricted shell access to that BitLocker-protected machine. Thankfully applying polices requireing BitLocker PIN and a BIOS password lock will prevent the exploit from running.
GreenPlasma is still awful, but shouldn’t make you spit your coffee out. There was only part of the exploit code published, though enough for someone to figure out the rest, and it does currently trigger a UAC prompt that can prevent it from doing it’s thing. If it does successfully run, you are facing a privilege escalation flaw. Nightmare-Eclipse may have more flaws ready to reveal, they’ve already ‘gifted’ us with three this year in addition to the ones from last year.
Their war against Microsoft continues as they post more flaws to GitHub.
The anonymous security researcher who has already maliciously exposed three Windows zero-days this year has revealed two more, dropping them just after Microsoft's monthly Patch Tuesday update.
More Tech News From Around The Web
- 18-year-old NGINX vulnerability allows DoS, potential RCE @ Bleeping Computer
- Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub @ The Register
- New Fragnesia Linux flaw lets attackers gain root privileges @ Bleeping Computer
- Windows Update Is Getting Automatic Rollbacks For Faulty Drivers @ Slashdot
- Dell confirms its SupportAssist software causes Windows BSOD crashes @ Bleeping Computer
- Kioxia XG10 Series PCIe Gen5 SSDs Announced @ ServeTheHome


