CVE-2026-45585ImportantDisclosedRevised 9 Jun
Windows BitLocker Security Feature Bypass Vulnerability
Assessment
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available. Mitigation FAQs Should I leverage the temporary mitigation? Microsoft recommends that you consider implementing these mitigations if you are concerned your devices and data are at risk of being compromised or stolen. For example, if your organization’s employees take their work devices home or on business tra…
- Severity
- Important
- CVSS base score
- 6.8CVSS:3.1/
AV:P/ AC:L/ PR:N/ UI:N/ S:U/ C:H/ I:H/ A:H/ E:P/ RL:W/ RC:C - Impact
- Security Feature Bypass
- EPSS, next 30 days
- 0.5%Higher than 39.8% of scored CVEs · FIRST model run 29 Sep 2026 · about EPSS
- Public exploit code
- No Nuclei template lists it
- Exploitability
- Exploitation More Likely
- Publicly disclosed
- Yes
- Customer action
- Required: apply the update
- Component
- Windows BitLocker
- Weakness
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- Issued by
- Microsoft
- Published
- 19 May 2026 · May 2026
- Last revised
- 9 Jun 2026Added links to June 2026 Windows security updates. Microsoft recommends installing this updates as soon as possible.
Updates that fix it
3 KBs| KB | Type | Restart | Applies to | Other CVEs |
|---|---|---|---|---|
| KB5094125 | Security Update | Required | Windows Server 2025, Windows Server 2025 (Server Core installation) | All CVEs in KB5094125 |
| KB5094126 | Security Update | Required | Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for x64-based Systems | All CVEs in KB5094126 |
| KB5095051 | Security Update | Required | Windows 11 version 26H1 for x64-based Systems | All CVEs in KB5095051 |