BitLocker Trust Break Follows Defender Offline Scan

A current patch level does not stop this one if Defender Offline Scan was ever used. GreatXML turns that setup step into a lasting trust break in WinRE, so a patched Windows 10 or 11 desktop can still expose BitLocker-protected data after a reboot into Recovery Mode. The public PoC plants XML state on the recovery partition and relies on WinRE trusting the offline-scan artifacts Defender left behind. Microsoft Defender offline scan and Windows Recovery Environment are the pieces in play here, and the result is unrestricted access to the protected volume without the BitLocker key. That shifts the story from a local SYSTEM-shell bug to a BitLocker bypass on systems that look healthy on paper. The risk persists anywhere recovery modes or other trusted-on-disk state can be rewritten and later honored by the boot environment.

Part of the PlainSec briefing for 2026-06-09

Every edition of this story: BitLocker Trust Break Follows Defender Offline Scan

Sources