Vulnerabilities · 89 days ago

BitLocker Trust Break Follows Defender Offline Scan

A current patch level does not stop this one if Defender Offline Scan was ever used. GreatXML turns that setup step into a lasting trust break in WinRE, so a patched Windows 10 or 11 desktop can still expose BitLocker-protected data after a reboot into Recovery Mode.

The public PoC plants XML state on the recovery partition and relies on WinRE trusting the offline-scan artifacts Defender left behind. Microsoft Defender offline scan and Windows Recovery Environment are the pieces in play here, and the result is unrestricted access to the protected volume without the BitLocker key.

That shifts the story from a local SYSTEM-shell bug to a BitLocker bypass on systems that look healthy on paper. The risk persists anywhere recovery modes or other trusted-on-disk state can be rewritten and later honored by the boot environment.

CVE-2026-41091

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to… EPSS 9% (93rd percentile). Microsoft patch: Release Notes.

CISA federal remediation date Jun 3 · date passed

CVE-2026-33825

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges… Microsoft patch: Release Notes.

CISA federal remediation date May 6 · date passed

Timeline

Sources

9 sources covering this story

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-06-09

Editions

Related stories