CVE-2026-45585 PUBLISHED

Windows BitLocker Security Feature Bypass Vulnerability

Assigner: microsoft
Reserved: 12.05.2026 Published: 19.05.2026 Updated: 20.05.2026

Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available.

Metrics

CVSS Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C
CVSS Score: 6.8

Product Status

Vendor Microsoft
Product Windows 11 Version 24H2
Versions
  • Version - is affected
Vendor Microsoft
Product Windows 11 Version 25H2
Versions
  • Version - is affected
Vendor Microsoft
Product Windows 11 version 26H1
Versions
  • Version - is affected
Vendor Microsoft
Product Windows Server 2025
Versions
  • Version - is affected
Vendor Microsoft
Product Windows Server 2025 (Server Core installation)
Versions
  • Version - is affected

References

Problem Types