CVE-2026-45585 is a Windows security feature bypass zero-day vulnerability, publicly known as “YellowKey", that targets the protections provided by Microsoft BitLocker full-disk encryption.
This vulnerability can allow an attacker with physical access to a Windows device to:
Vulnerability details:
Microsoft has officially disclosed CVE-2026-45585 today. While a permanent patch is not yet available, Microsoft has released a mitigation script that removes the “autofstx.exe” entry from the BootExecute REG_MULTI_SZ value in the offline SYSTEM registry hive of the Windows Recovery Environment (WinRE), preventing the executable from running during boot. To know more about the mitigation refer to:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585