Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit

The Hacker News by The Hacker News
May 20, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananMay 20, 2026Vulnerability / Encryption

Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week.

The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass.

“Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as ‘YellowKey,'” the tech giant said in an advisory. “The proof of concept for this vulnerability has been made public, violating coordinated vulnerability best practices.”

The issue impacts Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows Server 2025, and Windows Server 2025 (Server Core installation).

YellowKey was disclosed by a security researcher named Chaotic Eclipse (aka Nightmare-Eclipse). It essentially allows placing specially crafted ‘FsTx’ files on a USB drive or EFI partition, plugging the USB drive into the target Windows computer with BitLocker protections turned on, rebooting into the Windows Recovery Environment (WinRE), and triggering a shell with unrestricted access by holding down the CTRL key.

“If you did everything properly, a shell will spawn with unrestricted access to the BitLocker protected volume,” the researcher noted in a GitHub post.

Redmond noted that successful exploitation could permit an attacker with physical access to sidestep the BitLocker Device Encryption feature on the system storage device and gain access to encrypted data.

To address the risk, the following mitigations have been outlined:

  • Mount the WinRE image on each device.
  • Mount the system registry hive of the mounted WinRE image.
  • Modify BootExecute by removing “autofstx.exe” value from Session Manager’s BootExecute REG_MULTI_SZ value.
  • Save and unload Registry hive.
  • Unmount and commit the updated WinRE image.
  • Reestablish BitLocker trust for WinRE.

“Specifically, you prevent the FsTx Auto Recovery Utility, autofstx.exe, from automatically starting when the WinRE image launches,” security researcher Will Dormann said. “With this change, the Transactional NTFS replaying that deletes winpeshl.ini no longer happens. It also recommends switching from TPM-only to TPM+PIN.”

Microsoft also emphasized that users can be safeguarded against exploitation by configuring BitLocker on already encrypted devices with “TPM-only” protector by switching to “TPM+PIN” mode via PowerShell, the command line, or the control panel. This will require a PIN to decrypt the drive at startup, effectively backing YellowKey attacks.

On devices that are not encrypted, administrators are advised to enable the “Require additional authentication at startup” option via Microsoft Intune or Group Policies and ensure that “Configure TPM startup PIN” is set to “Require startup PIN with TPM.”



Source link

The Hacker News

The Hacker News

Next Post
ZTE präsentiert sich auf der GSMA M360 LATAM 2026 und treibt die Umgestaltung künftiger Geschäftsmodelle voran – wechselseitige Integration von KI und Netzwerken

ZTE präsentiert sich auf der GSMA M360 LATAM 2026 und treibt die Umgestaltung künftiger Geschäftsmodelle voran - wechselseitige Integration von KI und Netzwerken

Recommended.

AI agents spark interest, concern for businesses in 2025

AI agents spark interest, concern for businesses in 2025

January 23, 2025
ITI’s The Intersect Tech Policy Summit Happening in Washington D.C. on February 3rd

ITI’s The Intersect Tech Policy Summit Happening in Washington D.C. on February 3rd

January 31, 2026

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio