New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files

uukelele2 pts0 comments

GitHub - MSNightmare/GreatXML: GreatXML bitlocker bypass vulnerability · GitHub

/" data-turbo-transient="true" />

Skip to content

Search or jump to...

Search code, repositories, users, issues, pull requests...

-->

Search

Clear

Search syntax tips

Provide feedback

--><br>We read every piece of feedback, and take your input very seriously.

Include my email address so I can be contacted

Cancel

Submit feedback

Saved searches

Use saved searches to filter your results more quickly

-->

Name

Query

To see all available qualifiers, see our documentation.

Cancel

Create saved search

Sign in

/;ref_cta:Sign up;ref_loc:header logged out"}"<br>Sign up

Appearance settings

Resetting focus

You signed in with another tab or window. Reload to refresh your session.<br>You signed out in another tab or window. Reload to refresh your session.<br>You switched accounts on another tab or window. Reload to refresh your session.

Dismiss alert

{{ message }}

MSNightmare

GreatXML

Public

Notifications<br>You must be signed in to change notification settings

Fork<br>162

Star<br>387

main

BranchesTags

Go to file

CodeOpen more actions menu

Folders and files<br>NameNameLast commit message<br>Last commit date<br>Latest commit

History<br>4 Commits<br>4 Commits

Recovery/WindowsRE

Recovery/WindowsRE

LICENSE

LICENSE

README.md

README.md

screenshot1.png

screenshot1.png

screenshot2.png

screenshot2.png

unattend.xml

unattend.xml

View all files

Repository files navigation

GreatXML

GreatXML bitlocker bypass vulnerability

Steps to reproduce,

If defender offline scan was initiated in the victim machine at any point then there is no need to login, the machine is automatically vulnerable. You will have to copy "unattend.xml" and "Recovery" directory to the root of the recovery partition then reboot to WinRE using shift + click on restart button, if everything was done correctly, a shell with unrestricted access to the bitlocker volume will spawn.

If defender offline scan was never initiated then you have to either login and initiate it yourself or figure out a way to boot into WinRE in offline scan state (I believe it should be very possible to do so without logging in) and follow steps above

If everything is done properly, this should be the result

About

GreatXML bitlocker bypass vulnerability

Resources

Readme

License

MIT license

Uh oh!

There was an error while loading. Please reload this page.

Activity

Stars

387<br>stars

Watchers

watching

Forks

162<br>forks

Report repository

Releases

No releases published

Packages

Uh oh!

There was an error while loading. Please reload this page.

Contributors

Uh oh!

There was an error while loading. Please reload this page.

You can’t perform that action at this time.

greatxml reload bitlocker recovery search files

Related Articles