The YellowKey Windows zero-day is a serious reminder that disk encryption is only as strong as the boot and recovery chain around it. According to the report, Microsoft is tracking the flaw as CVE-2026-45585, a BitLocker security feature bypass where a public proof-of-concept can allow access to protected drives by abusing crafted FsTx files through WinRE. In simpler terms: the drive may be encrypted, but the recovery environment can become the weak door left conveniently open, because apparently security architecture enjoys irony.
Microsoft has shared mitigations while a full security update is pending. Administrators should remove the autofstx.exe entry from the Session Manager BootExecute value, re-establish BitLocker trust for WinRE using Microsoft’s mitigation guidance, and move encrypted devices from TPM-only mode to TPM+PIN mode so a pre-boot PIN is required before drive decryption. For new deployments, organizations should enforce “Require additional authentication at startup” through Intune or Group Policy and require a startup PIN with TPM.
This issue is especially important for laptops, privileged admin systems, executive devices, field machines, and any endpoint that may be lost, stolen, or physically accessed. BitLocker should not be treated as a magic checkbox. Security teams need to validate recovery partition integrity, control boot paths, monitor unauthorized WinRE/EFI changes, enforce pre-boot authentication where risk demands it, and ensure recovery keys are protected.
The larger lesson is that endpoint security must include physical-access threat scenarios. Encryption, secure boot, recovery environments, endpoint hardening, and identity controls all need to work together. A protected drive is not truly protected if attackers can manipulate the boot or recovery process to bypass that protection. Encryption is a wall; the boot chain is the gate. Leaving the gate weak and admiring the wall is, sadly, very on-brand for enterprise security.
Microsoft has shared mitigations for YellowKey, a recently disclosed Windows BitLocker zero-day vulnerability that grants access to protected drives. [...]
Source: Microsoft shares mitigation for YellowKey Windows zero-day via Bleeping Computer — published 20 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.