FSR Onimusha: Way of the Sword Steam Deck Performance Guide NINTENDO SWITCH 2 Digimon Story: Time Stranger DLC ‘A Hero’s Eternal Legacy’ Announced PLAYSTATION 5 Cygames Launches Where the Seeds Fall for PS5, Switch 2, and PC PLAYSTATION 5 Dragon Ball Xenoverse 3 Trailer Reveals New Android Avatar Race PLAYSTATION 5 Uncanyon Puzzle Adventure Announced for PS5, Xbox Series, Switch 2, and PC NINTENDO Final Fantasy Resonance Demo Now Live With Save Carryover HANDHELD GAMING FunnyPlaying Retro Pixel MiniGB Brings Game Boy Cartridges to a 2.6-Inch Handheld CONSOLES LEGO PlayStation Set Ships October 4 for $180 With Opening Disc Drive NINTENDO SWITCH How To Fish Console Availability: PS5, Xbox Series X|S, and Switch DLSS NVIDIA DLSS Multi Frame Generation Mod Brings Blackwell Tech to RTX 40 Series GAMES Killing Floor 3 Update 2.017 Fixes Stuttering and Buffs Damage PC HARDWARE Acer EP130K ePaper Monitor: 13.3-inch 3.2K Display Ships in 2027 AYANEO MSI Claw 8 EX AI+ Gets $1,499 Price Cut With Arc B370 GPU GAMES GTA 6 Miami Marketing Blocked by Sheriff Over Crime Stereotypes

Microsoft Issues Interim Mitigation for YellowKey BitLocker Bypass CVE-2026-45585

Daniel Cross 2 min read

Microsoft releases interim mitigation steps for the publicly disclosed YellowKey BitLocker bypass (CVE-2026-45585) and recommends TPM+PIN mode.

Microsoft Issues Interim Mitigation for YellowKey BitLocker Bypass CVE-2026-45585
SOFTWARE AND UPDATES

Microsoft has released interim mitigation guidance for YellowKey, a publicly disclosed BitLocker bypass tracked as CVE-2026-45585. The company confirmed it is working on a permanent fix and urged administrators across affected Windows versions to apply the interim steps immediately.

Interim mitigation guidance released for YellowKey BitLocker bypass CVE-2026-45585

The exploit uses Transactional NTFS to delete winpeshl.ini within the WinRE recovery environment, which spawns an unrestricted shell instead of loading the standard recovery interface. Microsoft addresses this by disabling autofstx.exe in the WinRE image. Administrators must mount the WinRE image on each affected device and remove the autofstx.exe entry from the Session Manager's BootExecute value.

Microsoft recommends moving high-risk devices from TPM-only BitLocker to TPM+PIN mode, which makes physical exploitation significantly more difficult. The vulnerability affects Windows 11 versions 24H2, 25H2, and 26H1 on x64 systems, along with Windows Server 2025 and its Server Core variant. Public technical analyses also flag Windows Server 2022 as potentially vulnerable under specific deployment conditions via the same WinRE recovery path flaw.

CVE-2026-45585 carries a CVSS score of 6.8 and requires physical access, but Microsoft rates exploitation as more likely due to the public proof of concept. Windows 10 does not experience issues because of differences in its WinRE configuration. The researcher behind the exploit released it publicly before Microsoft issued any guidance.

Microsoft has not confirmed when a full update will arrive for this vulnerability.

Source: NotebookCheck