Microsoft has released interim mitigation guidance for YellowKey, a publicly disclosed BitLocker bypass tracked as CVE-2026-45585. The company confirmed it is working on a permanent fix and urged administrators across affected Windows versions to apply the interim steps immediately.
Interim mitigation guidance released for YellowKey BitLocker bypass CVE-2026-45585
The exploit uses Transactional NTFS to delete winpeshl.ini within the WinRE recovery environment, which spawns an unrestricted shell instead of loading the standard recovery interface. Microsoft addresses this by disabling autofstx.exe in the WinRE image. Administrators must mount the WinRE image on each affected device and remove the autofstx.exe entry from the Session Manager's BootExecute value.
Microsoft recommends moving high-risk devices from TPM-only BitLocker to TPM+PIN mode, which makes physical exploitation significantly more difficult. The vulnerability affects Windows 11 versions 24H2, 25H2, and 26H1 on x64 systems, along with Windows Server 2025 and its Server Core variant. Public technical analyses also flag Windows Server 2022 as potentially vulnerable under specific deployment conditions via the same WinRE recovery path flaw.
CVE-2026-45585 carries a CVSS score of 6.8 and requires physical access, but Microsoft rates exploitation as more likely due to the public proof of concept. Windows 10 does not experience issues because of differences in its WinRE configuration. The researcher behind the exploit released it publicly before Microsoft issued any guidance.
Microsoft has not confirmed when a full update will arrive for this vulnerability.
Source: NotebookCheck




Discussion
0 comments