GreatXML's BitLocker Bypass Claim Falls Short — For Now
A pseudonymous researcher dropped an alleged WinRE-based BitLocker exploit days after Patch Tuesday. A respected vulnerability analyst couldn't replicate it. The researcher is already hunting a fix.

The exploit is called GreatXML. It arrived Thursday, attributed to a researcher operating under the names Nightmare Eclipse and Chaotic Eclipse — the same individual who has published eight Windows zero-days in recent months, several timed deliberately to follow Microsoft's Patch Tuesday cycle.
The claimed mechanism: copy two XML files (unattend.xml and Recovery/WindowsRE/ReAgent.xml) to the Windows Recovery Environment partition, which sits outside the encrypted volume, then reboot into WinRE. According to the researcher's notes, machines where Windows Defender Offline Scan was previously initiated would automatically spawn a shell with unrestricted access to the BitLocker volume — no credentials required.
That last part matters enormously. BitLocker's entire value proposition is protecting data on an unattended or stolen device. If the volume unlocks only after login, there is no bypass — just an elaborate way to do what an authenticated admin could already do.
Vulnerability analyst Will Dormann tested the technique across three Windows 11 versions and could not reproduce the described behavior. His assessment: the spawned CMD.EXE instance appears only when the next Defender Offline Scan is triggered, not the one prior. Triggering a Defender Offline Scan requires both an active Windows login and administrative credentials. Microsoft's own documentation confirms this — the scan demands elevated privileges and forces a reboot into WinRE to execute outside the OS, specifically to address kernel-level threats like rootkits.
If Dormann's read is correct, GreatXML as currently written requires the very access it claims to bypass.
Nightmare Eclipse did not respond to Dormann's analysis directly. Instead, the researcher posted publicly asking whether anyone knows of a method to trigger a Defender Offline Scan solely by editing ReAgent.xml — suggesting active work toward an alternate exploitation path, potentially one that avoids the login prerequisite entirely.
The researcher's blog post on Blogger disappeared shortly after publication; the researcher attributes the removal to Google. A GitHub repository hosting earlier proof-of-concept exploits was also taken down, a move the researcher attributes to Microsoft. That latter action drew pushback from segments of the security community, given GitHub's longstanding role as a repository for legitimate security research.
Two days before GreatXML, the same researcher published RoguePlanet, an alleged privilege escalation zero-day in Windows Defender. The back-to-back release follows an established pattern — dropping disclosures immediately after Patch Tuesday to maximize the window before Microsoft can issue a fix.
Dormann's inability to replicate GreatXML does not close the matter. Eclipse has demonstrated functional exploits before. A flaw in the current writeup does not preclude a corrected version, or an independent researcher adapting the technique. Organizations relying on BitLocker for endpoint data protection — particularly those with device-loss exposure — should monitor this one closely as it develops.



