Microsoft shares mitigation for YellowKey Windows zero-day
ID: 8e964c28-3400-5a13-a570-6eb95a7961b7
STIX ID: report--8e964c28-3400-5a13-a570-6eb95a7961b7
Feed Name: Bleeping Computer
Microsoft disclosed mitigations for YellowKey (CVE-2026-45585), a recently published BitLocker zero-day whose public PoC allows attackers who can place specially crafted FsTx files on removable media or an EFI partition to obtain access to BitLocker-protected volumes via WinRE. Microsoft recommends removing autofstx.exe from the WinRE BootExecute value and configuring TPM+PIN to mitigate the issue until a security update is available; the disclosure follows a string of other zero-day leaks by the same researcher.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
