New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
A researcher says GreatXML can bypass BitLocker by placing XML files on the recovery partition and booting into WinRE after a Defender offline scan.
Intelligence analysis by GPT-5.4 Mini

Security researcher Chaotic Eclipse released GreatXML, a Windows BitLocker bypass that allegedly works by copying two XML files into the recovery partition and then entering Windows Recovery Environment. The same researcher had just published a Microsoft Defender exploit and previously released another BitLocker bypass.
A lock on a suitcase is only useful if nobody can sneak around it. This story says a clever trick with recovery files may let someone open a Windows-protected drive by using the computer’s emergency repair mode.
Analysis
What happened
Security researcher Chaotic Eclipse, also known as Nightmare-Eclipse and MSNightmare, published a new Windows BitLocker bypass called GreatXML. The article says the researcher described it as an accidental discovery that took about four hours to find.
How it works
According to the report, the exploit involves copying an unattend.xml file and a second XML file at Recovery/WindowsRE/ReAgent.xml into the root of the recovery partition. After that, the system is rebooted into Windows Recovery Environment (WinRE) by holding Shift while clicking Restart in the Windows power menu. If the steps are done correctly, the result is a shell with unrestricted access to the BitLocker-protected volume.
The researcher said the issue is tied to systems that have used Windows Defender Offline Scan. In their words, if that scan was ever initiated, the machine is automatically vulnerable to the BitLocker bypass. They also noted uncertainty about whether the bug can be triggered without ever using the offline scan feature, though they believe it may be possible.
Context
GreatXML arrived soon after RoguePlanet, a zero-day flaw in Microsoft Defender that the article says enables local privilege escalation to SYSTEM. The same researcher also previously released YellowKey, another BitLocker bypass that Microsoft patched as part of this week’s Patch Tuesday updates.
Taken together, the article frames GreatXML as part of a short run of local Windows security issues affecting both Defender and BitLocker, with the recovery environment playing a central role in the attack path.
Key points
- Chaotic Eclipse published a BitLocker bypass named GreatXML.
- The method uses `unattend.xml` and `ReAgent.xml` on the recovery partition.
- Booting into WinRE after a Defender offline scan can yield shell access to the BitLocker volume.
- The researcher had recently posted a separate Microsoft Defender exploit.
- The article says Microsoft already patched a prior BitLocker bypass from the same researcher.
If Microsoft can reproduce the issue, it can likely harden the recovery path and close off this bypass in a future update. The report also gives defenders a concrete place to look: systems that used Defender Offline Scan and recovery-partition XML files.
If the technique holds up, local attackers could use it to get around BitLocker’s protection on vulnerable machines. The concern is bigger if the trigger state can be reached without obvious user action, because that would broaden the number of affected systems.



