Microsoft releases mitigations for the “YellowKey” vulnerability, tracked as CVE-2026-45585, which is described as a BitLocker security feature bypass. The flaw is publicly disclosed and is addressed as a zero-day that can be used to bypass protections associated with Windows full-disk encryption, potentially enabling attackers to access users’ data. Sources note that successful exploitation requires physical access to an affected device.
Pending a full fix, Microsoft provides guidance to help reduce exposure. SecurityWeek reports that the mitigation works by preventing the FsTx Auto Recovery Utility from starting when the Windows Recovery Environment (WinRE) image launches. Help Net Security describes Microsoft’s step-by-step mitigation advice intended to protect affected Windows devices until a permanent patch is available. The Hacker News adds that Microsoft released the mitigation following last week’s public disclosure and identifies CVE-2026-45585 with a CVSS score of 6.8, describing it as a security feature bypass rather than a direct credential attack.