logo

CVE-2026-45585: YellowKey BitLocker Bypass Exposes Encrypted Data on Windows Devices

ID: 491e1b35-b724-50f4-9d70-e6f9c8b7b615

STIX ID: report--491e1b35-b724-50f4-9d70-e6f9c8b7b615

Feed Name: SOC Prime Blog

Threat Score
65/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: SOC Prime Team

...
...

CVE-2026-45585 ("YellowKey") is a BitLocker security-feature bypass that leverages crafted FsTx files loaded via USB or EFI and abuses the Windows Recovery Environment to obtain an unrestricted shell and access encrypted volumes on affected Windows 11 (24H2/25H2/26H1) and Windows Server 2025 systems; a public proof-of-concept has been released which lowers replication barriers. Microsoft recommends two mitigations: remove autofstx.exe from the offline WinRE BootExecute setting and reseal WinRE, or require TPM+PIN startup authentication; detection is difficult because the attack occurs pre-boot and there are no vendor-published IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.