Microsoft Mitigates YellowKey BitLocker Bypass Vulnerability CVE-2026-45585

The company has released a mitigation for the publicly disclosed zero-day flaw that allows attackers to bypass BitLocker security features.

Illustration: Microsoft Mitigates YellowKey BitLocker Bypass Vulnerability CVE-2026-45585

The company has released a mitigation for the publicly disclosed zero-day flaw that allows attackers to bypass BitLocker security features.

  • Microsoft released mitigation for CVE-2026-45585, a BitLocker bypass vulnerability known as YellowKey
  • The zero-day flaw has a CVSS score of 6.8 and was publicly disclosed last week
  • The vulnerability allows attackers to bypass BitLocker security features

Microsoft has released a mitigation for a BitLocker bypass vulnerability designated CVE-2026-45585, known publicly as YellowKey, following its disclosure last week.

The zero-day vulnerability carries a CVSS score of 6.8 and has been classified as a BitLocker security feature bypass, according to The Hacker News. Microsoft acknowledged awareness of the security flaw in a statement released Tuesday.

BitLocker is Microsoft’s disk encryption technology designed to protect data by encrypting entire disk volumes. The YellowKey vulnerability represents a significant security concern as it potentially allows attackers to circumvent these encryption protections.

The vulnerability was publicly disclosed last week, prompting Microsoft to develop and release mitigation measures. The company confirmed it is aware of the security feature bypass vulnerability that has been publicly referenced as YellowKey.

Details about the specific attack vector or exploitation method have not been fully disclosed in the available information. The rapid response from Microsoft suggests the company is treating this as a priority security issue given BitLocker’s widespread use in enterprise environments.

The mitigation release comes as organisations increasingly rely on disk encryption to protect sensitive data, particularly in hybrid work environments where devices may be more vulnerable to physical access attacks.

Why It Matters

BitLocker bypass vulnerabilities represent critical risks for CISOs as they undermine fundamental data protection controls that many organisations rely on for compliance and data security. This vulnerability could potentially expose encrypted data in scenarios where physical device access is obtained, affecting risk assessments and incident response procedures.

The public disclosure of YellowKey increases the urgency for organisations to implement Microsoft’s mitigation measures, particularly given the potential for exploitation in environments where device theft or unauthorised physical access is possible.

What To Do Now

  • Review and apply Microsoft’s mitigation measures for CVE-2026-45585 across all BitLocker-enabled systems
  • Assess current BitLocker deployment configurations and verify encryption settings are properly implemented
  • Monitor Microsoft security advisories for additional guidance on the YellowKey vulnerability

Sources