CVE-2026-45585

Published May 20, 2026

Last updated 3 days ago

Overview

Description
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available. Mitigation FAQs Should I leverage the temporary mitigation? Microsoft recommends that you consider implementing these mitigations if you are concerned your devices and data are at risk of being compromised or stolen. For example, if your organization’s employees take their work devices home or on business travel. What impact to service availability/management could be caused by implementing the mitigations? Implementing these mitigations will not impact service availability or management operations. Do customers need to revert the changes made to mitigate the vulnerability once the security update to protect against this vulnerability is available? No. The security update will maintain the mitigation's behavior once the security update is installed. I am using TPM+PIN, am I at risk of this vulnerability being exploited No, if you are using TPM+PIN the vulnerability is not exploitable.
Source
secure@microsoft.com
NVD status
Modified
Products
windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.8
Impact score
5.9
Exploitability score
0.9
Vector string
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
MEDIUM

Weaknesses

secure@microsoft.com
CWE-77

Social media

Hype score
Not currently trending
  1. YellowKey exploit bypasses BitLocker TPM protection on Windows 11/Server 2022-2025 by exploiting WinRE vulnerability CVE-2026-45585. Microsoft 🇺🇸 patched in updates, but unpatched systems remain vulnerable to physical access attacks. Technical breakdown: • Exploits flaw

    @DFIR_Radar

    9 Jun 2026

    157 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  2. CVE-2026-45585: ⚠️ Microsoft Releases Mitigation for Windows BitLocker Security Bypass 0-Day Vulnerability Source: Microsoft has disclosed a critical zero-day vulnerability in Windows BitLocker, tracked as CVE-2026-45585, that allows threat actors…

    @lyrie_ai

    7 Jun 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Top 5 Trending CVEs: 1 - CVE-2026-45585 2 - CVE-2025-36911 3 - CVE-2026-31525 4 - CVE-2026-0257 5 - CVE-2026-28910 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    1 Jun 2026

    104 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. BREAKING: Reports claim "Nightmare Eclipse" has been removed from GitHub and GitLab. Linked CVEs: • CVE-2026-45585 • CVE-2026-45498 • CVE-2026-41091 No official confirmation from MITRE or Microsoft MSRC. https://t.co/IgJH6qkwXl #CyberSecurity #InfoSec #CVE #MasaudSec #h

    @masaudsec

    31 May 2026

    149 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2026-45585 YELLOWKEY 🔐 https://t.co/iR3778CHMG #Microsoft #YellowKey #0day #CVE202645585 https://t.co/YxjiF7xq8O

    @0xBlackash

    31 May 2026

    77 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Top 5 Trending CVEs: 1 - CVE-2026-48095 2 - CVE-2026-45585 3 - CVE-2026-40369 4 - CVE-2026-42826 5 - CVE-2026-0257 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    31 May 2026

    148 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. ثغرة تجاوز تشفير القرص في ويندوز كُشفت علناً ثم رُقّعت رسمياً المعرّف : CVE-2026-45585 الاسم العلني : YellowKey درجة الخطورة : 6.8 (CVSS) - Security Feature Bypass الحل : May 2026 Microsoft mi

    @KasperskyDev

    30 May 2026

    77 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 “Nightmare Eclipse” Zero-Day Update: • GitHub repos taken down • Moved to GitLab + statement • MSRC claims (CVE-2026-45585) • UnDefend & RedSun mentioned • July 14 may bring updates Follow to access the Exposed Zeroday file https://t.co/ArxLJUKvQB

    @redteamfq

    30 May 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Top 5 Trending CVEs: 1 - CVE-2025-55182 2 - CVE-2026-5194 3 - CVE-2026-48095 4 - CVE-2026-23652 5 - CVE-2026-45585 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    29 May 2026

    97 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Top 5 Trending CVEs: 1 - CVE-1999-0997 2 - CVE-2026-45659 3 - CVE-2026-23652 4 - CVE-2026-45585 5 - CVE-2024-52577 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    28 May 2026

    98 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  11. ثغرة في بيئة استرداد ويندوز تتيح تجاوز تشفير القرص بوصول مادي — دليل استغلال منشور علناً المعرّف : CVE-2026-45585 درجة الخطورة : 6.8 (CVSS) - Medium الإصدارات المتأثرة

    @KasperskyDev

    27 May 2026

    184 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. Microsoft、ゼロデイ 脆弱性のRedSun(CVE-2026-41091)とUnDefend(CVE-2026-45498)の緊急パッチを公開・YellowKey(CVE-2026-45585)は「緩和策のみ」 https://t.co/0SdkLe41S3 #セキュリティ対策Lab #security #securitynews

    @securityLab_jp

    24 May 2026

    152 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  13. CVE-2026-45585 (CVSS 6.8) "YellowKey" bypasses BitLocker via Windows Recovery Environment using crafted FsTx files on USB/EFI. Affects Windows 11 24H2+ and Server 2025. Apply Microsoft's WinRE mitigation or switch to TPM+PIN authentication. #DFIR_Radar https://t.co/Ld31NmNemF

    @DFIR_Radar

    22 May 2026

    113 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  14. 【YellowKey:BitLocker回避への緩和策が公開】 BitLocker回避手法「YellowKey」について、Microsoftが緩和策を示しました。 CVE-2026-45585として扱われ、Windows 11やWindows Server 2025が影響を受けると報じられています。

    @01ra66it

    21 May 2026

    217 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Microsoft has released mitigations addressing the “YellowKey” BitLocker bypass vulnerability (CVE-2026-45585), which impacted Windows 11 version 26H1, 24H2, 25H2 for x64 Systems, Windows Server 2025, and Windows Server 2025 (Server Core installation). https://t.co/La9PlNEnNh

    @pr0rat

    21 May 2026

    130 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  16. マイクロソフトは、BitLockerのバイパス脆弱性「YellowKey」(CVE-2026-45585)に対する対策を提供しています Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585) #HelpNetSecurity (May 20) https://t.co/c73POcCZeT

    @foxbook

    21 May 2026

    258 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  17. 윈도우 비트락커 우회 취약점(CVE-2026-45585) 패치 설치 권고 (출처 : Virus My.. | 블로그) https://t.co/4FDRYtsfyI

    @virusmyths

    20 May 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit https://t.co/WAEBC3FFGi

    @JosephLykowski

    20 May 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Microsoft acknowledges YellowKey CVE-2026-45585 (CVSS 6.8) BitLocker bypass affecting Windows 11 24H2+ and Server 2025. Physical attack spawns unrestricted shell via crafted FsTx files. Disable autofstx.exe and enable TPM+PIN immediately. #DFIR_Radar https://t.co/cYYOAZWYLH

    @DFIR_Radar

    20 May 2026

    127 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  20. New BitLocker bypass exploits Windows Recovery Environment to decrypt drives using Microsoft's own tools. No patch available despite CVE assignment. Researcher withholding follow-on attack that also defeats startup PIN protection. Technical details: • CVE-2026-45585 affects ht

    @DFIR_Radar

    20 May 2026

    154 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  21. 🚨 CVE-2026-45585: Microsoft releases mitigation for YellowKey BitLocker bypass. This WinRE-related flaw may allow encrypted data access if an attacker has physical access to the device. https://t.co/3zPIIbFy4w #Microsoft #BitLocker #YellowKey #CVE #WindowsSecurity #Vulert

    @vulert_official

    20 May 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 📌 استكمال مايكروسوفت لمعالجة ثغرة YellowKey لتجاوز BitLocker CVE-2026-45585 أصدرت مايكروسوفت معالجة لثغرة أمنية في BitLocker تسمى YellowKey، والتي تم الإعلان عنها علنًا الأسبو

    @MisbarSec

    20 May 2026

    165 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit https://t.co/yzgU69Evab

    @Tech_Newsletter

    20 May 2026

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585) https://t.co/tfceoUo4m3

    @TheCyberSecHub

    20 May 2026

    341 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  25. Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit https://t.co/ADqQaQFjqo

    @wvipersg

    20 May 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit https://t.co/CeFLcuyyPn

    @TheCyberSecHub

    20 May 2026

    326 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585): Microsoft is working on a fix for CVE-2026-45585 (aka “Yellowkey”), a vulnerability that can be used by attackers to bypass protections offered by BitLocker, the… https://t.co/jhCbekFT

    @shah_sheikh

    20 May 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585) - https://t.co/u3QiZ499X6 - @Microsoft @msftsecurity @MsftSecIntel @ncsc_nl @wdormann #CVE #EXploit #PoC #VulnerabilityDisclosure #Windows #WindowsServer #Cybersecurity #CybersecurityNews htt

    @helpnetsecurity

    20 May 2026

    330 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations