{"id":983,"date":"2026-05-20T09:47:10","date_gmt":"2026-05-20T09:47:10","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=983"},"modified":"2026-05-20T09:47:10","modified_gmt":"2026-05-20T09:47:10","slug":"microsoft-releases-mitigation-for-yellowkey-bitlocker-bypass-cve-2026-45585-exploit","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=983","title":{"rendered":"Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">May 20, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Encryption<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh8DmW5nAG63-9iR2RmnP7i3GVJ9EBtLznscnnjROZ-DWRALYo0zsPNjUm2J6khkqSDJiX5Gmwb8sxPh4jHRcsJWFhKSdxZzz4D2f5bOahbfcnmQrUdvhyphenhyphenNVrE-LFMUhhf6rvSyxG2CoVhEFxbZSpEc0y52PM-qxwn02cDP3K3hEzf1nqcRNZEG1wOTjAiQ\/s1700-e365\/bitlocker-exploit.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week.<\/p>\n<p>The zero-day flaw, now tracked as <b>CVE-2026-45585<\/b>, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass.<\/p>\n<p>\u00abMicrosoft is aware of a security feature bypass vulnerability in Windows publicly referred to as &#8216;YellowKey,'\u00bb the tech giant <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-45585\">said<\/a> in an advisory. \u00abThe proof of concept for this vulnerability has been made public, violating coordinated vulnerability best practices.\u00bb<\/p>\n<p>The issue impacts Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows Server 2025, and Windows Server 2025 (Server Core installation).<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>YellowKey was disclosed by a security researcher named Chaotic Eclipse (aka Nightmare-Eclipse). It essentially allows placing specially crafted &#8216;FsTx&#8217; files on a USB drive or EFI partition, plugging the USB drive into the target Windows computer with BitLocker protections turned on, rebooting into the Windows Recovery Environment (WinRE), and triggering a shell with unrestricted access by holding down the CTRL key.<\/p>\n<p>\u00abIf you did everything properly, a shell will spawn with unrestricted access to the BitLocker protected volume,\u00bb the researcher noted in a GitHub post.<\/p>\n<p>Redmond noted that successful exploitation could permit an attacker with physical access to sidestep the BitLocker Device Encryption feature on the system storage device and gain access to encrypted data.<\/p>\n<p>To address the risk, the following mitigations have been outlined:<\/p>\n<ul>\n<li>Mount the WinRE image on each device.<\/li>\n<li>Mount the system registry hive of the mounted WinRE image.<\/li>\n<li>Modify BootExecute by removing \u00abautofstx.exe\u00bb value from Session Manager&#8217;s BootExecute REG_MULTI_SZ value.<\/li>\n<li>Save and unload <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/sysinfo\/registry-hives\">Registry hive<\/a>.<\/li>\n<li>Unmount and commit the updated WinRE image.<\/li>\n<li>Reestablish BitLocker trust for WinRE.<\/li>\n<\/ul>\n<p>\u00abSpecifically, you prevent the FsTx Auto Recovery Utility, autofstx.exe, from automatically starting when the WinRE image launches,\u00bb security researcher Will Dormann <a href=\"https:\/\/infosec.exchange\/@wdormann\/116604563324444723\">said<\/a>. \u00abWith this change, the Transactional NTFS replaying that deletes winpeshl.ini no longer happens. It also recommends switching from TPM-only to TPM+PIN.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Microsoft also emphasized that users can be safeguarded against exploitation by <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/security\/operating-system-security\/data-protection\/bitlocker\/configure\">configuring BitLocker<\/a> on already encrypted devices with \u00abTPM-only\u00bb protector by switching to \u00abTPM+PIN\u00bb mode via PowerShell, the command line, or the control panel. This will require a PIN to decrypt the drive at startup, effectively backing YellowKey attacks.<\/p>\n<p>On devices that are not encrypted, administrators are advised to enable the \u00abRequire additional authentication at startup\u00bb option via Microsoft Intune or Group Policies and ensure that \u00abConfigure TPM startup PIN\u00bb is set to \u00abRequire startup PIN with TPM.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802May 20, 2026Vulnerability \/ Encryption Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The zero-day flaw, now tracked&hellip;<\/p>\n","protected":false},"author":1,"featured_media":984,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1668,394,1742,120,147,1740,1739,1741],"class_list":["post-983","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-bitlocker","tag-bypass","tag-cve202645585","tag-exploit","tag-microsoft","tag-mitigation","tag-releases","tag-yellowkey"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/983","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=983"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/983\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/984"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=983"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=983"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=983"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}