CVE detail
CVE-2026-45585
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available. Mitigation FAQs Should I leverage the temporary mitigation? Microsoft recommends that you consider implementing these mitigations if you are concerned your devices and data are at risk of being compromised or stolen. For example, if your organization’s employees take their work devices home or on business travel. What impact to service availability/management could be caused by implementing the mitigations? Implementing these mitigations will not impact service availability or management operations. Do customers need to revert the changes made to mitigate the vulnerability once the security update to protect against this vulnerability is available? No. The security update will maintain the mitigation's behavior once the security update is installed. I am using TPM+PIN, am I at risk of this vulnerability being exploited No, if you are using TPM+PIN the vulnerability is not exploitable.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 28.3 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 18.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
16 source links · newest first
- Record Microsoft Patch Tuesday, fresh zero-dayHelp Net Security
Microsoft marked its largest-ever Patch Tuesday this month, by shipping fixes for nearly 200 vulnerabilities. Within hours, “Nightmare Eclipse”, the researcher behind weeks of escalating Windows exploit releases, dropped a proof-of-concept exploit for a new zero-day: “RoguePlanet”, which abuses a race condition in Windows Defender to spawn a command shell running with SYSTEM-level privileges. Various researchers have confirmed that the PoC exploit works to achieve local privilege escalation. “In initial development, it was confirmed that … More →
newswww.helpnetsecurity.comJun 10, 2026, 10:56 AM - Microsoft Releases Record-Breaking Patch Tuesday With 208 CVEsSecurity Affairs
Microsoft Patch Tuesday security updates for June 2026 fix a record 208 CVEs, including one actively exploited zero-day and multiple critical RCE flaws. Microsoft Patch Tuesday security updates for June 2026 mark a record. Microsoft shipped fixes for 208 CVEs across Windows, Office, Azure, Exchange, Hyper-V, Secure Boot, BitLocker, and a range of AI tooling. […]
newssecurityaffairs.comJun 9, 2026, 10:55 PM y to respond without out-of-cycle patches. At time of writing, Microsoft has provided mitigation advice and patches for CVE-2026-33825 , CVE-2026-45585 , CVE-2026-45498 , and CVE-2026-41091 , leaving only two elevation of privilege vulnerabilities unpatched, known as MiniPlasma and GreenPlasma. However, a recent blog post by Nightmare Eclipse with the
vendorwww.rapid7.comJun 9, 2026, 9:04 PMbe the flaw known as Bitskrieg and a collaboration between Chaotic Eclipse (Nightmare Eclipse) and Jonas L . Important CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability CVE-2026-49160 is a denial of service (DoS) vulnerability affecting HTTP.sys. It received a CVSSv3 score of 7.5 and is rated as important. It was assessed as “Exploitation More
vendorwww.tenable.comJun 9, 2026, 6:19 PM- The June 2026 Security Update ReviewZero Day Initiative
loser look at some of the more interesting updates for this month, starting with the bug being exploited in the wild. - CVE-2026-41091 - Microsoft Defender Elevation of Privilege Vulnerability Since Microsoft doesn’t provide info on how widespread exploitation is, we must read some tea leaves. For this patch, several different people were acknowledged,
vendorwww.thezdi.comJun 9, 2026, 6:12 PM Microsoft responds to backlash over its threats of legal action against researchers who publicly disclose zero-day vulnerabilities.
newswww.securityweek.comJun 3, 2026, 9:57 AM- Microsoft and security researcher’s dueling posts about cybersecurity disclosures get nastyCSO Online
Microsoft and a prominent cybersecurity researcher have gotten into a very public and rather personal exchange of unpleasantries about what responsible cybersecurity disclosures should mean in 2026. A cybersecurity researcher going by the name Nightmare Eclipse, who has disclosed several cybersecurity holes before patches were available, posted that he had tried to contact Microsoft officials […]
newswww.csoonline.comMay 29, 2026, 11:53 PM - Microsoft Calls the Zero-Day Dumps Irresponsible. The Researcher Says Microsoft Started It.Security Affairs
A researcher dropped 6 Windows zero-days with no warning. Three are now exploited in the wild. Microsoft is angry. The researcher says Microsoft ignored them first. Over the past month, a researcher going by Chaotic Eclipse, also known as Nightmare-Eclipse, publicly released details of six unpatched vulnerabilities in Windows components including Defender and BitLocker. No […]
newssecurityaffairs.comMay 29, 2026, 10:51 AM - Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploitedHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise GitHub CISO Alexis Wales has named the malicious VS Code extension behind the breach they suffered at the hands of the threat group TeamPCP: Nx Console, a popular developer tool with 2.2 million installs. Earbud sensors can authenticate users by their heartbeat, study finds Researchers built a continuous authentication … More →
newswww.helpnetsecurity.comMay 24, 2026, 8:00 AM - Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498)Help Net Security
Attackers are exploiting two Microsoft Defender vulnerabilities (CVE-2026-41091 and CVE-2026-45498), Microsoft acknowledged and CISA confirmed by adding them to its Known Exploited Vulnerabilities catalog. The vulnerabilities CVE-2026-41091 allows for local privilege elevation (LPE), and is caused by the Microsoft Malware Protection Engine improperly resolving links before accessing files. “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” Microsoft noted. CVE-2026-45498 can cause a denial-of-service (DoS) state, i.e., it can be used to prevent … More →
newswww.helpnetsecurity.comMay 21, 2026, 10:57 AM Microsoft says it is considering a patch for a zero-day vulnerability, dubbed YellowKey, that allows attackers with access to a Windows device to bypass Bitlocker encryption protection and read and write files. The flaw was disclosed last week, and there is already a public proof of concept available. The company issued an advisory Tuesday saying […]
newswww.csoonline.comMay 21, 2026, 1:08 AMThe exploitation is mitigated by preventing the FsTx Auto Recovery Utility from starting when the WinRE image launches.
newswww.securityweek.comMay 20, 2026, 3:39 PM- Microsoft issues YellowKey mitigation, no patch yetSecurity Affairs
Microsoft acknowledged the YellowKey BitLocker bypass flaw and released mitigations, urging admins to disable autofstx.exe and enable TPM+PIN. A week after Chaotic Eclipse publicly dropped the YellowKey vulnerability, Microsoft acknowledged it and published a mitigation. Not a patch, a mitigation. The distinction matters, and we will get to why. The flaw, tracked as CVE-2026-45585 (CVSS […]
newssecurityaffairs.comMay 20, 2026, 3:07 PM - Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585)Help Net Security
Microsoft is working on a fix for CVE-2026-45585 (aka “Yellowkey”), a vulnerability that can be used by attackers to bypass protections offered by BitLocker, the full-disk encryption feature built into Windows, and access users’ data. In the meantime, the company has provided step-by-step mitigation advice to protect affected Windows devices from exploitation. CVE-2026-45585 and the YellowKey exploit CVE-2026-45585 is a security feature bypass vulnerability that can only be exploited if the attacker has physical access … More →
newswww.helpnetsecurity.comMay 20, 2026, 8:33 AM No excerpt available.
Exploitgithub.comMay 20, 2026, 12:16 AMMicrosoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available.
vendormsrc.microsoft.comMay 19, 2026, 2:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
7 repository references · best confidence 0.99 · max 33 stars
- yellowkeys/YellowKey-Bitlocker-CVE-2026-45585High confidencegithubRepository topic discovery33 starsDiscovered Jul 20, 2026, 8:51 PM
- yellow-key/yellowkey-bitlockerHigh confidencegithubDiscovery source unavailable26 starsDiscovered Jul 9, 2026, 6:51 PM
- yellowkey-bitlocker/YellowKey-BitlockerHigh confidencegithubRepository topic discovery17 starsDiscovered Jul 19, 2026, 6:51 PM
- mysterioinfinino-rgb/YellowKey-Bitlocker-CVE-2026-45585High confidencegithubRepository topic discovery1 starsDiscovered Jul 20, 2026, 6:51 PM
- codespacey68/yellowkey-bitlockerHigh confidencegithubDiscovery source unavailable1 starsDiscovered Jul 9, 2026, 6:30 PM
- boobalover7/YellowKey-Bitlocker-CVE-2026-45585High confidencegithubRepository topic discovery0 starsDiscovered Jul 21, 2026, 10:51 PM
- Nightmare-Eclipse/YellowKeyHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 15, 2026, 12:21 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-58635CVSS 7.8 · High
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
- CVE-2026-32183CVSS 7.8 · High
Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execute code locally.
- CVE-2026-50488CVSS 7.8 · High
Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-54100CVSS 7.8 · High
Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally.
- CVE-2026-58638CVSS 6.0 · Medium
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
- CVE-2026-58637CVSS 7.0 · High
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.