• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
microsoft releases mitigation for yellowkey bitlocker bypass cve 2026 45585 exploit

Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit

You are here: Home / General Cyber Security News / Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit
May 20, 2026

Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week.

The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass.

“Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as ‘YellowKey,'” the tech giant said in an advisory. “The proof of concept for this vulnerability has been made public, violating coordinated vulnerability best practices.”

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The issue impacts Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows Server 2025, and Windows Server 2025 (Server Core installation).

Cybersecurity

YellowKey was disclosed by a security researcher named Chaotic Eclipse (aka Nightmare-Eclipse). It essentially allows placing specially crafted ‘FsTx’ files on a USB drive or EFI partition, plugging the USB drive into the target Windows computer with BitLocker protections turned on, rebooting into the Windows Recovery Environment (WinRE), and triggering a shell with unrestricted access by holding down the CTRL key.

“If you did everything properly, a shell will spawn with unrestricted access to the BitLocker protected volume,” the researcher noted in a GitHub post.

Redmond noted that successful exploitation could permit an attacker with physical access to sidestep the BitLocker Device Encryption feature on the system storage device and gain access to encrypted data.

To address the risk, the following mitigations have been outlined:

  • Mount the WinRE image on each device.
  • Mount the system registry hive of the mounted WinRE image.
  • Modify BootExecute by removing “autofstx.exe” value from Session Manager’s BootExecute REG_MULTI_SZ value.
  • Save and unload Registry hive.
  • Unmount and commit the updated WinRE image.
  • Reestablish BitLocker trust for WinRE.

“Specifically, you prevent the FsTx Auto Recovery Utility, autofstx.exe, from automatically starting when the WinRE image launches,” security researcher Will Dormann said. “With this change, the Transactional NTFS replaying that deletes winpeshl.ini no longer happens. It also recommends switching from TPM-only to TPM+PIN.”

Cybersecurity

Microsoft also emphasized that users can be safeguarded against exploitation by configuring BitLocker on already encrypted devices with “TPM-only” protector by switching to “TPM+PIN” mode via PowerShell, the command line, or the control panel. This will require a PIN to decrypt the drive at startup, effectively backing YellowKey attacks.

On devices that are not encrypted, administrators are advised to enable the “Require additional authentication at startup” option via Microsoft Intune or Group Policies and ensure that “Configure TPM startup PIN” is set to “Require startup PIN with TPM.”

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «grafana github breach exposes source code via tanstack npm attack Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit
  • Grafana GitHub Breach Exposes Source Code via TanStack npm Attack
  • GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories
  • Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps
  • DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability
  • The New Phishing Click: How OAuth Consent Bypasses MFA
  • Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare
  • SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
  • Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer
  • GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials

Copyright © TheCyberSecurity.News, All Rights Reserved.