AI description
CVE-2026-50507 is a security feature bypass vulnerability found in Windows BitLocker. This flaw allows an unauthorized attacker to circumvent BitLocker's protection mechanisms through a physical attack on the system. The vulnerability enables access to encrypted data, effectively undermining the intended security provided by BitLocker. This issue was publicly disclosed before a patch was made available and is associated with a broader set of disclosures concerning potential bypasses affecting Windows recovery and encryption protections, sometimes referred to as "YellowKey" or "bitskrieg."
- Description
- Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025
CVSS 3.1
- Type
- Primary
- Base score
- 6.8
- Impact score
- 5.9
- Exploitability score
- 0.9
- Vector string
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- MEDIUM
- secure@microsoft.com
- CWE-306
- Hype score
- Not currently trending
Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507) https://t.co/neWCvEN5xs https://t.co/QsZTwrH4Ri
@TechMash365
13 Jun 2026
19 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507) https://t.co/KAPOi3wFOQ https://t.co/4JIN3hhotI
@TechMash365
12 Jun 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507) https://t.co/cJj0ldVXQV https://t.co/nRU5mY6Wgz
@secured_cyber
12 Jun 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Windowsを使っている方、今月のパッチは急いでほしい。ゼロデイ3件を含む200個の脆弱性が一度に修正された。↓ ・CVE-2026-50507:BitLockerのセキュリティ機能をバイパス可能 ・CVE-2026-45586:Collaborative Translation Frame
@hasamayo1217
11 Jun 2026
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft、2026年6月定例パッチで史上最多206件の脆弱性を修正-3件のゼロデイや危険な脆弱性含む(CVE-2026-50507,CVE-2026-45586,CVE-2026-47291,CVE-2026-49160) https://t.co/CpGVUObyFk #セキュリティ対策Lab #security #securitynews
@securityLab_jp
11 Jun 2026
114 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507) https://t.co/VQhHQS97ni https://t.co/BDfQM9FjuD
@pcasano
10 Jun 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507) https://t.co/PjVt6R1Rth https://t.co/j1CNDgwNsZ
@IT_Peurico
10 Jun 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507) https://t.co/BC6vg2Nnza https://t.co/IpTcDIfuvU
@ggrubamn
10 Jun 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507) https://t.co/yFcY4xI8ol https://t.co/Yk0zKMNYd6
@Art_Capella
10 Jun 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【2026年6月 Patch Tuesday 要注意CVE】 🔴 CVE-2026-45657 CVSS9.8:Windowsカーネル未認証RCE(ワーム化可能) 🟠 CVE-2026-45586:入力メソッドCTFMONの権限昇格(公開済みゼロデイ) 🟡 CVE-2026-49160 CVSS7.5:HTTP/2 Bomb(DoS) 🟡
@holy519
10 Jun 2026
165 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
5月に紹介したBitLockerバイパスのゼロデイ「YellowKey」に続き、新たなBitLockerバイパス脆弱性CVE-2026-50507が、6月の月例セキュリティ更新で修正されました。物理アクセスを持つ未認証の攻撃者が、本来必要な認証
@MalwareBibleJP
10 Jun 2026
1704 Impressions
6 Retweets
29 Likes
8 Bookmarks
0 Replies
0 Quotes
Microsoftは6月のPatch Tuesdayで、BitLockerのセキュリティ機能を回避できる脆弱性CVE-2026-50507を公表した。物理的にデバイスへアクセスできる攻撃者がBitLocker Device
@yousukezan
10 Jun 2026
1675 Impressions
5 Retweets
6 Likes
2 Bookmarks
0 Replies
0 Quotes
🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗝𝘂𝗻𝗲 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 After just one month without zero-days, we’re back to 𝟯 𝗻𝗲𝘄 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆𝘀 and multiple nasty 9+ vuln
@horizon_secured
9 Jun 2026
1557 Impressions
1 Retweet
16 Likes
5 Bookmarks
2 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "039BC4EF-6E49-4A8C-B1A4-BFAD9F24EC01",
"versionEndExcluding": "10.0.14393.9234",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "2221A0A5-45F3-4903-943A-19E7AA69496B",
"versionEndExcluding": "10.0.14393.9234",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "03A4C97D-FE89-4367-9A0E-E4E65BD49E18",
"versionEndExcluding": "10.0.17763.8880",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "FE809AA0-E917-495F-BB11-59215F47E14F",
"versionEndExcluding": "10.0.17763.8880",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "3E87DD4E-44FC-4B9A-99AB-D1DB3C67EF79",
"versionEndExcluding": "10.0.19044.7417",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "A21A9BC4-DE4F-46BE-944F-AD6CAA92BF32",
"versionEndExcluding": "10.0.19044.7417",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "911336E9-FAEA-4EB5-96D7-8049AE622C61",
"versionEndExcluding": "10.0.19044.7417",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "B8BB8399-35C5-4654-A679-5E105773615B",
"versionEndExcluding": "10.0.19045.7417",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "55571EDC-8323-4BAE-B363-113ACEF55CB2",
"versionEndExcluding": "10.0.19045.7417",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "D14AC77E-34F3-4704-A068-D9020FF60A8C",
"versionEndExcluding": "10.0.19045.7417",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "92508776-88BE-4872-99DB-1F690F71ADEF",
"versionEndExcluding": "10.0.22631.7219",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "410079AC-180E-4D7F-B7F6-784E36FEA036",
"versionEndExcluding": "10.0.22631.7219",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "32DB4863-6880-40B4-8EC1-9E0F40E81D7F",
"versionEndExcluding": "10.0.26100.8655",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "E691C9E5-5271-436D-A7FD-C25BEA4D447D",
"versionEndExcluding": "10.0.26100.8655",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "1D3DEE4A-9959-4716-BC39-35660AC22BC4",
"versionEndExcluding": "10.0.26200.8655",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "1000C085-A5D7-4027-B9C1-6AE7DA468FB7",
"versionEndExcluding": "10.0.26200.8655",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "9C7AD7ED-307B-40B9-B706-45FB178C36D8",
"versionEndExcluding": "10.0.28000.2269",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "8967AF79-CAD0-4F87-85A5-95D031C9FEFA",
"versionEndExcluding": "10.0.28000.2269",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
"matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B3F7E1F6-48D5-4ECB-9BF8-4238903FC194",
"versionEndExcluding": "10.0.14393.9234",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"matchCriteriaId": "07C08212-A30E-4434-A17C-542E45D1E272",
"versionEndExcluding": "10.0.17763.8880",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"matchCriteriaId": "27363D97-D4A9-4709-9854-F78F7EBCFB27",
"versionEndExcluding": "10.0.20348.5256",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "E127A6E6-C261-4039-8A13-A2FAC4606573",
"versionEndExcluding": "10.0.26100.32995",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]