CVE-2026-45585
Windows BitLocker Security Feature Bypass Vulnerability
Published: May 19, 2026Updated: May 20, 2026 Sources: CVE List NVD
6.8CVSS
MEDIUMMicrosoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available.
EPSS Score
0.1%
Top 68.6%
CISA KEV
Not in KEV
Exploits
No Known Exploits
Remediation
Patch Available
CVSS Vector Breakdown
Exploitability
AV:PAttack VectorPhysical
AC:LAttack ComplexityLow
PR:NPrivileges RequiredNone
UI:NUser InteractionNone
Scope
S:UScopeUnchanged
Impact
C:HConfidentialityHigh
I:HIntegrityHigh
A:HAvailabilityHigh
Weaknesses
Affected Products
and 4 more affected products View all →
Attack Graph
Products CVE Techniques Tactics
Click technique nodes to view MITRE ATT&CK details. Scroll to zoom, drag to pan.
Exploitability
Official Patch Available
MITRE ATT&CK
1 technique Execution
References
Timeline
Published
May 19, 2026
Last Updated
May 20, 2026
News mentions
10- New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Filesen·The Hacker News· Summary only·
- ИБ-исследователь Nightmare Eclipse раскрыл 0-day-уязвимость в Microsoft Defenderru-ru·Хакер (xakep.ru)· Source-only·
- Microsoft исправила более 200 уязвимостей и шесть 0-day в своих продуктахru-ru·Хакер (xakep.ru)· Source-only·
- Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-daysen-us·BleepingComputer· Summary only·
- Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugsen·The Hacker News· Summary only·
- Rapid7en·Rapid7 Blog·
- Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flawsen-us·BleepingComputer· Summary only·
- В Microsoft заявили, что не будут преследовать исследователей за публикацию 0-day-эксплоитовru-ru·Хакер (xakep.ru)· Source-only·
- В VS Code нашли 0-day-уязвимость, позволявшую похищать токены GitHubru-ru·Хакер (xakep.ru)· Source-only·
- Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removalen·The Hacker News· Summary only·
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-45585 and every CVE in our database. Create a free account — no credit card required.
Create Free AccountPlain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows