PoC Archive PoC Archive

tag

WinRE

  • N/A binary HIGH

    GreatXML — WinRE / Defender Offline-Scan Trust-Boundary Abuse → BitLocker Bypass (No CVE)

    GreatXML abuses the trust boundary around Microsoft Defender's Offline Scan feature, which reboots a Windows machine into WinRE (Windows PE) and runs OfflineScannerShell.exe with elevated, pre-BitLocker-unlock trust. The ReAgent.xml recovery-configuration…

    Unpatched 2026-07-27
  • CVE-2026-45585 misc MEDIUM 6.1

    YellowKey — BitLocker Bypass via WinRE autofstx.exe (CVE-2026-45585)

    CVE-2026-45585 (YellowKey) is a zero-day physical-access vulnerability discovered in May 2026 that allows an attacker with physical access to a Windows 11 device to fully bypass BitLocker disk encryption without the PIN, password, or recovery key. The…

    Patched 2026-06-26