- Description
- Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available. Mitigation FAQs Should I leverage the temporary mitigation? Microsoft recommends that you consider implementing these mitigations if you are concerned your devices and data are at risk of being compromised or stolen. For example, if your organization’s employees take their work devices home or on business travel. What impact to service availability/management could be caused by implementing the mitigations? Implementing these mitigations will not impact service availability or management operations. Do customers need to revert the changes made to mitigate the vulnerability once the security update to protect against this vulnerability is available? No. The security update will maintain the mitigation's behavior once the security update is installed. I am using TPM+PIN, am I at risk of this vulnerability being exploited No, if you are using TPM+PIN the vulnerability is not exploitable.
- Source
- secure@microsoft.com
- NVD status
- Modified
- Products
- windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2025
CVSS 3.1
- Type
- Secondary
- Base score
- 6.8
- Impact score
- 5.9
- Exploitability score
- 0.9
- Vector string
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- MEDIUM
- secure@microsoft.com
- CWE-77
- Hype score
- Not currently trending
YellowKey exploit bypasses BitLocker TPM protection on Windows 11/Server 2022-2025 by exploiting WinRE vulnerability CVE-2026-45585. Microsoft 🇺🇸 patched in updates, but unpatched systems remain vulnerable to physical access attacks. Technical breakdown: • Exploits flaw
@DFIR_Radar
9 Jun 2026
157 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-45585: ⚠️ Microsoft Releases Mitigation for Windows BitLocker Security Bypass 0-Day Vulnerability Source: Microsoft has disclosed a critical zero-day vulnerability in Windows BitLocker, tracked as CVE-2026-45585, that allows threat actors…
@lyrie_ai
7 Jun 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2026-45585 2 - CVE-2025-36911 3 - CVE-2026-31525 4 - CVE-2026-0257 5 - CVE-2026-28910 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
1 Jun 2026
104 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
BREAKING: Reports claim "Nightmare Eclipse" has been removed from GitHub and GitLab. Linked CVEs: • CVE-2026-45585 • CVE-2026-45498 • CVE-2026-41091 No official confirmation from MITRE or Microsoft MSRC. https://t.co/IgJH6qkwXl #CyberSecurity #InfoSec #CVE #MasaudSec #h
@masaudsec
31 May 2026
149 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-45585 YELLOWKEY 🔐 https://t.co/iR3778CHMG #Microsoft #YellowKey #0day #CVE202645585 https://t.co/YxjiF7xq8O
@0xBlackash
31 May 2026
77 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2026-48095 2 - CVE-2026-45585 3 - CVE-2026-40369 4 - CVE-2026-42826 5 - CVE-2026-0257 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
31 May 2026
148 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
ثغرة تجاوز تشفير القرص في ويندوز كُشفت علناً ثم رُقّعت رسمياً المعرّف : CVE-2026-45585 الاسم العلني : YellowKey درجة الخطورة : 6.8 (CVSS) - Security Feature Bypass الحل : May 2026 Microsoft mi
@KasperskyDev
30 May 2026
77 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 “Nightmare Eclipse” Zero-Day Update: • GitHub repos taken down • Moved to GitLab + statement • MSRC claims (CVE-2026-45585) • UnDefend & RedSun mentioned • July 14 may bring updates Follow to access the Exposed Zeroday file https://t.co/ArxLJUKvQB
@redteamfq
30 May 2026
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2025-55182 2 - CVE-2026-5194 3 - CVE-2026-48095 4 - CVE-2026-23652 5 - CVE-2026-45585 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
29 May 2026
97 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-1999-0997 2 - CVE-2026-45659 3 - CVE-2026-23652 4 - CVE-2026-45585 5 - CVE-2024-52577 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
28 May 2026
98 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
ثغرة في بيئة استرداد ويندوز تتيح تجاوز تشفير القرص بوصول مادي — دليل استغلال منشور علناً المعرّف : CVE-2026-45585 درجة الخطورة : 6.8 (CVSS) - Medium الإصدارات المتأثرة
@KasperskyDev
27 May 2026
184 Impressions
1 Retweet
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Microsoft、ゼロデイ 脆弱性のRedSun(CVE-2026-41091)とUnDefend(CVE-2026-45498)の緊急パッチを公開・YellowKey(CVE-2026-45585)は「緩和策のみ」 https://t.co/0SdkLe41S3 #セキュリティ対策Lab #security #securitynews
@securityLab_jp
24 May 2026
152 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
CVE-2026-45585 (CVSS 6.8) "YellowKey" bypasses BitLocker via Windows Recovery Environment using crafted FsTx files on USB/EFI. Affects Windows 11 24H2+ and Server 2025. Apply Microsoft's WinRE mitigation or switch to TPM+PIN authentication. #DFIR_Radar https://t.co/Ld31NmNemF
@DFIR_Radar
22 May 2026
113 Impressions
0 Retweets
2 Likes
0 Bookmarks
1 Reply
0 Quotes
【YellowKey:BitLocker回避への緩和策が公開】 BitLocker回避手法「YellowKey」について、Microsoftが緩和策を示しました。 CVE-2026-45585として扱われ、Windows 11やWindows Server 2025が影響を受けると報じられています。
@01ra66it
21 May 2026
217 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft has released mitigations addressing the “YellowKey” BitLocker bypass vulnerability (CVE-2026-45585), which impacted Windows 11 version 26H1, 24H2, 25H2 for x64 Systems, Windows Server 2025, and Windows Server 2025 (Server Core installation). https://t.co/La9PlNEnNh
@pr0rat
21 May 2026
130 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
マイクロソフトは、BitLockerのバイパス脆弱性「YellowKey」(CVE-2026-45585)に対する対策を提供しています Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585) #HelpNetSecurity (May 20) https://t.co/c73POcCZeT
@foxbook
21 May 2026
258 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
윈도우 비트락커 우회 취약점(CVE-2026-45585) 패치 설치 권고 (출처 : Virus My.. | 블로그) https://t.co/4FDRYtsfyI
@virusmyths
20 May 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit https://t.co/WAEBC3FFGi
@JosephLykowski
20 May 2026
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft acknowledges YellowKey CVE-2026-45585 (CVSS 6.8) BitLocker bypass affecting Windows 11 24H2+ and Server 2025. Physical attack spawns unrestricted shell via crafted FsTx files. Disable autofstx.exe and enable TPM+PIN immediately. #DFIR_Radar https://t.co/cYYOAZWYLH
@DFIR_Radar
20 May 2026
127 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
New BitLocker bypass exploits Windows Recovery Environment to decrypt drives using Microsoft's own tools. No patch available despite CVE assignment. Researcher withholding follow-on attack that also defeats startup PIN protection. Technical details: • CVE-2026-45585 affects ht
@DFIR_Radar
20 May 2026
154 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🚨 CVE-2026-45585: Microsoft releases mitigation for YellowKey BitLocker bypass. This WinRE-related flaw may allow encrypted data access if an attacker has physical access to the device. https://t.co/3zPIIbFy4w #Microsoft #BitLocker #YellowKey #CVE #WindowsSecurity #Vulert
@vulert_official
20 May 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
📌 استكمال مايكروسوفت لمعالجة ثغرة YellowKey لتجاوز BitLocker CVE-2026-45585 أصدرت مايكروسوفت معالجة لثغرة أمنية في BitLocker تسمى YellowKey، والتي تم الإعلان عنها علنًا الأسبو
@MisbarSec
20 May 2026
165 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit https://t.co/yzgU69Evab
@Tech_Newsletter
20 May 2026
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585) https://t.co/tfceoUo4m3
@TheCyberSecHub
20 May 2026
341 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit https://t.co/ADqQaQFjqo
@wvipersg
20 May 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit https://t.co/CeFLcuyyPn
@TheCyberSecHub
20 May 2026
326 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585): Microsoft is working on a fix for CVE-2026-45585 (aka “Yellowkey”), a vulnerability that can be used by attackers to bypass protections offered by BitLocker, the… https://t.co/jhCbekFT
@shah_sheikh
20 May 2026
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585) - https://t.co/u3QiZ499X6 - @Microsoft @msftsecurity @MsftSecIntel @ncsc_nl @wdormann #CVE #EXploit #PoC #VulnerabilityDisclosure #Windows #WindowsServer #Cybersecurity #CybersecurityNews htt
@helpnetsecurity
20 May 2026
330 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "1799DC19-34BA-42B4-A6DC-02774202DE22",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "AAAB3FDE-4FF2-47DE-9BDA-25B2855054E7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "DA9F6F61-46D3-4ECD-8B5D-1484222B7364",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9B12238F-DF99-4247-B645-259C3FD98F61",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]