CVE-2026-45585Patch(microsoft / windows_11_24h2)

CRITICALCVSS 6.8 · MEDIUM

Exploitation observed; activity peaked at 51 mentions and remains active

Immediate actions

  • Patch microsoft windows_11_24h2 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available. Mitigation FAQs Should I leverage the temporary mitigation? Microsoft recommends that you consider implementing these mitigations if you are concerned your devices and data are at risk of being compromised or stolen. For example, if your organization’s employees take their work devices home or on business travel. What impact to service availability/management could be caused by implementing the mitigations? Implementing these mitigations will not impact service availability or management operations. Do customers need to revert the changes made to mitigate the vulnerability once the security update to protect against this vulnerability is available? No. The security update will maintain the mitigation's behavior once the security update is installed. I am using TPM+PIN, am I at risk of this vulnerability being exploited No, if you are using TPM+PIN the vulnerability is not exploitable.

9.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_24h2
  • windows_11_25h2
  • windows_11_26h1
  • windows_server_2025

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 121 mentions across 29 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 9 signals
  • PoC mentioned or linked in 20 signals
  • Patch or workaround mentioned in 85 signals
  • Technical details provided in 64 signals
  • Disclosure: 17 classified signals
  • General: 15 classified signals
  • Peaked 28d ago at 51 mentions (2026-05-20); latest day: 1
  • 121 total mentions across 29 days

Affected systems

Vendors
Products
windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2025

Deep dive

Activity timeline121 mentions / 29d
013263851Mentions · 2026-05-20: 51Mentions · 2026-05-21: 20Mentions · 2026-05-22: 3Mentions · 2026-05-23: 2Mentions · 2026-05-24: 1Mentions · 2026-05-25: 2Mentions · 2026-05-26: 4Mentions · 2026-05-27: 1Mentions · 2026-05-28: 1Mentions · 2026-05-29: 4Mentions · 2026-05-30: 1Mentions · 2026-05-31: 3Mentions · 2026-06-01: 1Mentions · 2026-06-02: 1Mentions · 2026-06-03: 2Mentions · 2026-06-07: 2Mentions · 2026-06-08: 1Mentions · 2026-06-09: 4Mentions · 2026-06-10: 3Mentions · 2026-06-12: 2Mentions · 2026-06-15: 3Mentions · 2026-06-16: 1Mentions · 2026-06-25: 1Mentions · 2026-07-03: 2Mentions · 2026-07-29: 1Mentions · 2026-08-04: 1Mentions · 2026-08-12: 1Mentions · 2026-08-25: 1Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-05-20: 7PoC Mentioned / Linked · 2026-05-21: 4PoC Mentioned / Linked · 2026-05-25: 1PoC Mentioned / Linked · 2026-05-27: 1PoC Mentioned / Linked · 2026-05-29: 1PoC Mentioned / Linked · 2026-05-31: 1PoC Mentioned / Linked · 2026-06-03: 1PoC Mentioned / Linked · 2026-06-09: 1PoC Mentioned / Linked · 2026-06-15: 1PoC Mentioned / Linked · 2026-08-04: 1PoC Mentioned / Linked · 2026-09-11: 1Exploit Tool / Code · 2026-05-20: 3Exploit Tool / Code · 2026-05-21: 1Exploit Tool / Code · 2026-05-23: 1Exploit Tool / Code · 2026-05-25: 1Exploit Tool / Code · 2026-05-31: 1Exploit Tool / Code · 2026-06-03: 1Exploit Tool / Code · 2026-06-15: 1Active Exploitation · 2026-05-20: 3Active Exploitation · 2026-05-25: 1Active Exploitation · 2026-06-03: 1Active Exploitation · 2026-06-15: 1Patch / Workaround · 2026-05-20: 43Patch / Workaround · 2026-05-21: 16Patch / Workaround · 2026-05-22: 3Patch / Workaround · 2026-05-23: 2Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-05-25: 1Patch / Workaround · 2026-05-26: 3Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-29: 1Patch / Workaround · 2026-05-30: 1Patch / Workaround · 2026-06-07: 1Patch / Workaround · 2026-06-09: 2Patch / Workaround · 2026-06-10: 1Patch / Workaround · 2026-06-12: 2Patch / Workaround · 2026-06-15: 3Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-07-29: 1Patch / Workaround · 2026-08-12: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-05-20: 35Technical Details · 2026-05-21: 13Technical Details · 2026-05-22: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-25: 1Technical Details · 2026-05-26: 2Technical Details · 2026-05-27: 1Technical Details · 2026-05-29: 1Technical Details · 2026-05-30: 1Technical Details · 2026-06-09: 1Technical Details · 2026-06-10: 2Technical Details · 2026-06-12: 1Technical Details · 2026-06-15: 2Technical Details · 2026-06-25: 1Technical Details · 2026-07-03: 105-2005-2205-2405-2605-2805-3006-0106-0306-0806-1006-1506-2507-2908-1209-11
Signal classification6 categories
Patch
7461.2%
Disclosure
1714.0%
General
1512.4%
PoC
97.4%
Active Exploitation
43.3%
Exploit
21.7%
Referenced assets60 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-2051
Active Exploitation2Disclosure6Patch42PoC1
2026-05-2120
Disclosure3Exploit1General1Patch13PoC2
2026-05-223
Patch3
2026-05-232
Disclosure1Patch1
2026-05-241
Patch1
2026-05-252
Active Exploitation1PoC1
2026-05-264
Disclosure1General1Patch2
2026-05-271
PoC1
2026-05-281
General1
2026-05-294
Disclosure1General3
2026-05-301
Patch1
2026-05-313
General2PoC1
2026-06-011
General1
2026-06-021
General1
2026-06-032
Disclosure1Exploit1
2026-06-072
Disclosure1Patch1
2026-06-081
General1
2026-06-094
General2Patch1PoC1
2026-06-103
Disclosure1General1Patch1
2026-06-122
Patch2
2026-06-153
Active Exploitation1Patch2
2026-06-161
Patch1
2026-06-251
Disclosure1
2026-07-032
Disclosure1General1
2026-07-291
Patch1
2026-08-041
PoC1
2026-08-121
Patch1
2026-08-251
Patch1
2026-09-111
PoC1
Full discourse20 posts
  • EnergíaVitalX 🇪🇸✨💚@OndaChispa33
    Disclosure

    Casi siempre es algo inofensivo (actualización automática, cambio en BIOS, etc.). Hay una vulnerabilidad reciente (YellowKey/CVE-2026-45585) que permite saltarse BitLocker con acceso físico usando un USB, pero en tu caso simplemente está pidiendo la clave legítima, así que es buena señal de que la protección sigue activa. Qué puedes hacer ahora: Intenta recuperar la clave desde otra cuenta Microsoft en **http://aka.ms/myrecoverykey** (necesitas acceder a la cuenta vinculada al PC). Si no tienes acceso a la cuenta, busca el código de 48 dígitos que Windows te mostró al activar BitLocker la primera vez (suele estar en tu cuenta Microsoft, OneDrive o impresa). Si no la encuentras y los datos son importantes, no fuerces nada y lleva el equipo a un técnico de confianza. Una vez dentro, puedes suspender BitLocker temporalmente o guardar la clave en un lugar seguro. Soy ingeniero de Microsoft jubilado.

    Post summary

    El texto informa sobre un CVE reciente que permite eludir BitLocker con acceso físico por USB, pero indica que la protección sigue activa y ofrece pasos para recuperar la clave.

    21220812539270.6K
    1.5K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    🚨 Microsoft released mitigations for YellowKey, a BitLocker bypass tracked as CVE-2026-45585. The flaw can let attackers with physical access access encrypted data via WinRE. Learn more: https://thehackernews.com/2026/05/microsoft-releases-mitigation-for.html https://t.co/eC1rANQLUS

    Post summary

    Microsoft has issued mitigations for the YellowKey BitLocker bypass (CVE-2026-45585), addressing a flaw that allows physical attackers to bypass encryption via WinRE. No exploit code or active attacks are mentioned.

    69523019540.7K
    1.9M followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    PoC

    الجهات الي تستخدم BitLocker عندي لكم خبر سيء … 😆 Nightmare-Eclipse رجع من جديد الباحث Nightmare-Eclipse نشر PoC على GitHub لثغرة YellowKey (CVE-2026-45585) الثغره تتجاوز حماية BitLocker في Windows 11 شروط استغلال الثغرة 🔹 الهجوم يحتاج وصول فيزيائي أو تعديل EFI partition 🔹 يضع ملفات FsTx في USB (Transactional NTFS) 🔹ـ WinRE يقراها ويمسح ملف winpeshl.ini 🔹 بدال شاشة طلب مفتاح BitLocker - يفتح CMD والهارديسك غير مشفر

    Post summary

    The tweet announces that researcher Nightmare‑Eclipse has released a Proof‑of‑Concept on GitHub for CVE‑2026‑45585, detailing the conditions for exploiting BitLocker without specifying active attacks or patches.

    716113110838.8K
    50.0K followersView on X
  • Cyber Security News@The_Cyber_News
    Patch

    ⚠️ Microsoft Releases Mitigation for Windows BitLocker Security Bypass 0-Day Vulnerability Source: https://cybersecuritynews.com/windows-bitlocker-yellowkey-mitigation/ Microsoft has disclosed a critical zero-day vulnerability in Windows BitLocker, tracked as CVE-2026-45585, that allows threat actors with physical access to bypass full-disk encryption entirely, potentially exposing sensitive data within minutes. The flaw was publicly disclosed on May 19, 2026, and while no active exploitation has been confirmed, Microsoft rates it as “Exploitation More Likely,” prompting urgent mitigation action. It resides within the Windows Recovery Environment (WinRE) and is tied to a critical exploit chain dubbed YellowKey, developed by researcher Nightmare-Eclipse and published on GitHub. #cybersecuritynews

    Post summary

    Microsoft has issued a mitigation for CVE-2026-45585, a Windows BitLocker bypass; a PoC is available on GitHub, but no confirmed active exploitation is reported.

    3291107268.5K
    68.9K followersView on X
  • Jörgen Nilsson@ccmexec
    Patch

    Updated guidance on BitLocker + Yellowkey - again, now with a script to configure the workaround. Time to test it out! https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585 #MSintune #Windows11 https://t.co/DeFmOry1nc

    Post summary

    Microsoft released guidance including a script to apply a workaround for CVE-2026-45585, indicating a patch or mitigation is available.

    211046383.0K
    7.8K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    مايكروسفت تهدد برفع قضايا على الباحث الامني Nightmare Eclipse بعد مابهدلهم ونشر 6 ثغرات 0day (RedSun) CVE-2026-41091 (UnDefend) CVE-2026-45498 (BlueHammer) CVE-2026-33825 (YellowKey) CVE-2026-45585 (GreenPlasma) (MiniPlasma) مو من صالحهم يعادون مجتمع الباحثين بهالطريقه https://t.co/bFoufGGRYW

    Post summary

    The tweet accuses Microsoft of threatening legal action against a researcher who disclosed six 0‑day CVEs, but it offers no technical details, PoC, or evidence of active exploitation.

    581453522.4K
    50.0K followersView on X
  • Es Geeks@EsGeeks
    Disclosure

    🛡️ Windows 11 llega vulnerable de fábrica. Una laptop nueva trae 4 configs por defecto que son agujeros documentados: - Recovery key de BitLocker a OneDrive - AI services activos - Telemetría on - BitLocker en TPM-only (CVE-2026-45585) 5 ajustes antes 1r arranque conectado 👇 https://t.co/dkYGHJyn3G

    Post summary

    The tweet announces that new Windows 11 laptops ship with four default configuration flaws, including a BitLocker vulnerability (CVE‑2026‑45585), but offers no PoC, exploit tool, active exploitation evidence, patch, or detailed technical information.

    111037261.4K
    22.2K followersView on X
  • Dark Web Informer@DarkWebInformer
    Patch

    Microsoft acknowledges the YellowKey BitLocker bypass vulnerability and releases mitigations https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585 https://t.co/HCOLpYioZS

    Post summary

    Microsoft acknowledges the YellowKey BitLocker bypass vulnerability (CVE‑2026‑45585) and has published mitigations.

    18335137.2K
    223.7K followersView on X
  • Harjit Dhaliwal@Hoorge
    Disclosure

    CVE-2026-45585 - Microsoft Security Update Guide - Windows BitLocker Security Feature Bypass Vulnerability and Mitigation aka "YellowKey" -https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585 #CyberSecurity #Windows #Bitlocker #MSintune #Vulnerability #MSRC https://t.co/HFOnj2R8mu

    Post summary

    The tweet links to Microsoft’s update guide for CVE-2026-45585, a Windows BitLocker bypass vulnerability, providing only a formal disclosure reference without PoC, exploit, or patch details.

    08123125.2K
    8.5K followersView on X
  • Jörgen Nilsson@ccmexec
    Patch

    Updated guidance on BitLocker - Yellowkey TPM+PIN is always a good idea, bad from user perspective but mitigated many vulnerabilities. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585

    Post summary

    The post announces updated guidance for BitLocker – Yellowkey, indicating TPM+PIN as a workaround to mitigate the CVE‑2026‑45585 vulnerability.

    4601541.6K
    7.8K followersView on X
  • 情報の灯台@joho_no_todai
    Patch

    BitLockerを回避するゼロデイ脆弱性「YellowKey」をめぐり、MicrosoftはCVE-2026-45585のアドバイザリで公開した研究者を「協調的開示のベストプラクティス違反」と明示した。 研究者のNightmare-Eclipseは「Microsoftが脆弱性報告に使っていたMSRCアカウントを一方的に削除し、説明を求めても応答がなかった」と主張している。 報告窓口を失った状態で「手順を踏まなかった」と呼べるかどうか、答えはまだどこにもない。 Windows 11とWindows Server 2025が対象で、暫定対処策は出たがパッチは未提供。 https://joho-todai.com/yellowkey-bitlocker-cve-2026-45585-microsoft-researcher-conflict/

    Post summary

    The post reports on a BitLocker bypass zero‑day (CVE‑2026‑45585) and the ensuing dispute with Microsoft over the researcher’s disclosure, noting provisional mitigations are available while an official patch is pending.

    0422011.8K
    11.1K followersView on X
  • SoyITPro@SoyITPro
    Patch

    Microsoft soluciona vulnerabilidad "YellowKey" que se saltaba Bitlocker. Vulnerabilidad publicada por Nightmare Eclipse y toda la polémica que se a formado con este personaje. - Windows 11 ⚡ KB5094126 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585

    Post summary

    Microsoft released patch KB5094126 to remediate CVE-2026-45585, a YellowKey flaw that permitted bypassing of Bitlocker.

    1301561.4K
    12.7K followersView on X
  • Blue Team News@blueteamsec1
    Patch

    Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit http://dlvr.it/TTzpPz #Microsoft #BitLocker #CyberSecurity #Vulnerability #CVE202645585 https://t.co/CrD0kUDQdR

    Post summary

    Microsoft has released a mitigation for the YellowKey BitLocker bypass vulnerability (CVE-2026-45585); the tweet offers no evidence of exploitation or a PoC.

    050992.0K
    57.5K followersView on X
  • Rahul Chavan@codecroc
    General

    @Pirat_Nation msrc revocation during active reports like cve-2026-45585 signals the breakdown happened at the disclosure process layer

    Post summary

    Mentions CVE-2026-45585 but provides no specific information on exploitation, patches, or technical details.

    0101625.0K
    82 followersView on X
  • Sami Laiho@samilaiho
    Patch

    Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit https://thehackernews.com/2026/05/microsoft-releases-mitigation-for.html

    Post summary

    Microsoft released a mitigation for the YellowKey BitLocker bypass CVE‑2026‑45585, but there is no indication of active exploitation or available PoC/exploit code. The post highlights the patch rather than an exploitation scenario.

    050851.5K
    30.6K followersView on X
  • Pltx@pulitux
    General

    @barckcode Mira esto por si te ayuda: https://www.fullstackevolved.com/es/blog/cve-2026-45585-yellowkey-bitlocker-2026-05-26/

    Post summary

    The tweet simply shares a link to a blog post about CVE-2026-45585 without providing any additional information or context.

    0006119.7K
    330 followersView on X
  • Azubuike Ibe@ai_dev_official
    Disclosure

    BitLocker enabled does not mean BitLocker protected. YellowKey just proved that. CVE-2026-45585 is a publicly disclosed BitLocker bypass affecting Windows 11 and Windows Server systems. It abuses the Windows Recovery Environment to gain access to encrypted volumes under physical-access conditions, without needing the recovery key. Default TPM-only deployments are the most exposed. That is the configuration most teams ship. Set it once, check the compliance box, move on. Meanwhile the recovery environment sitting on the same drive becomes the attack surface. This hits laptops, developer workstations, field devices, and servers in colo or shared facilities where physical access cannot be fully controlled. The uncomfortable truth: full-disk encryption is one layer. It was never meant to be the only one. If your boot flow, recovery partition, and physical access paths are not hardened, encryption alone will not save you. That has always been true. YellowKey just made it impossible to ignore. Microsoft has published interim mitigation guidance while a permanent fix is in progress. Practical starting points: move from TPM-only to TPM plus PIN, restrict and harden WinRE, tighten BIOS and UEFI protections, enforce physical access controls, and run tamper monitoring on endpoints that leave the building. Comment “YELLOWKEY” and I will send you my Windows encryption and physical security hardening playbook with production-ready patterns. Follow me first so the DM lands. Have you reviewed your BitLocker and WinRE configuration lately? My name is Azubuike Ibe and I write about the assumptions inside security stacks that attackers test before defenders do. Share this with someone on your team who thinks BitLocker alone is enough. #Cybersecurity #BitLocker #WindowsSecurity #PhysicalSecurity #DevSecOps

    Post summary

    YellowKey exposed a BitLocker bypass (CVE‑2026‑45585) that exploits WinRE via physical access, prompting Microsoft to release interim mitigations while a permanent fix is in progress.

    0307694
    1.5K followersView on X
  • tamaiyutaro@tamai_pc
    Disclosure

    通称 YellowKey と呼ばれる BitLocker の脆弱性に関するマイクロソフトからの情報が公開されています。 CVE-2026-45585 Windows BitLocker Security Feature Bypass Vulnerability https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585

    Post summary

    Microsoft has publicly disclosed information about the YellowKey BitLocker security feature bypass vulnerability (CVE-2026-45585), but no proof-of-concept, exploit, active exploitation, or patch details are mentioned.

    05171945
    1.4K followersView on X
  • Kamil Zmeškal ⚛@KamilZm
    Patch

    Microsoft zveřejnil postup, jak se bránit proti zranitelnosti Bitlockeru (CVE-2026-45585), postup nevyžaduje mít nastaven PIN https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585 https://t.co/SlxBK77L5v

    Post summary

    Microsoft released guidance to mitigate the BitLocker vulnerability CVE‑2026‑45585 without requiring a PIN, providing a workable defense.

    03065657
    1.8K followersView on X
  • 🕳@sekurlsa_pw
    Patch

    Mitigation for YellowKey ( @ChaoticEclipse0) from Microsoft: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585 Mitigations are to change the WinRe enviroment registry and include a pre-boot PIN.

    Post summary

    Microsoft has issued mitigation guidance for CVE‑2026‑45585, instructing users to modify the WinRe environment registry and enable a pre‑boot PIN.

    11062895
    2.6K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2025---

Explore more