CVE-2026-45585 (YellowKey): BitLocker Bypass via FsTx + WinRE — Physical Access, No Credentials Needed

Technical root cause of YellowKey: bypassing BitLocker full-disk encryption via WinRE transaction replay without knowing user credentials.

📌
Security Roundup Series: Week of May 28, 2026 • 4 min read deep dive
⚠️
Threat Intelligence & Technical Specs: CVE ID: CVE-2026-45585 Severity: CVSS 6.8 Status: Physical access BitLocker bypass Target Component: Windows Recovery Environment (WinRE)

CVE-2026-45585 (CVSS 6.8), publicly known as YellowKey, is a BitLocker security feature bypass disclosed by researcher Chaotic Eclipse (aka Nightmare-Eclipse). Microsoft published a mitigation on May 20, 2026. A public PoC is available. Physical access to the target machine is required — no credentials, no software installation, no network access needed.

Attack Chain

YellowKey abuses a behavioral trust assumption in the Windows Recovery Environment (WinRE):

  1. Attacker crafts specially constructed FsTx files on a USB drive or EFI partition.
  2. USB drive is plugged into the target BitLocker-protected Windows system.
  3. System is rebooted into WinRE (Windows Recovery Environment).
  4. WinRE's autofstx.exe (FsTx Auto Recovery Utility) executes automatically via the BootExecute registry value.
  5. autofstx.exe performs cross-volume TxF transaction replay, which deletes winpeshl.ini — the file that normally controls WinRE startup.
  6. With winpeshl.ini absent, the attacker holds CTRL during boot to spawn an unrestricted command shell with full access to the decrypted BitLocker volume.

LevelBlue's updated May 22 analysis confirmed YellowKey can be chained with MiniPlasma for a complete "physical access to full domain persistence" attack path: YellowKey bypasses BitLocker to access the decrypted volume, then MiniPlasma escalates from any local account to SYSTEM.

Affected Versions

  • Windows 11 version 26H1 for x64-based Systems
  • Windows 11 Version 24H2 for x64-based Systems
  • Windows 11 Version 25H2 for x64-based Systems
  • Windows Server 2025
  • Windows Server 2025 (Server Core installation)

Attack Scenarios

Because YellowKey requires only brief physical access and leaves no persistent hardware artifacts, it is viable across: device theft, border device inspections, insider threats, and supply chain exposure.

Remediation

Microsoft's mitigation removes the autofstx.exe entry from the BootExecute registry value in WinRE:

  1. Mount the WinRE image: reagentc /mountre /path C:\WinRE
  2. Mount the system registry hive of the mounted WinRE image.
  3. Remove autofstx.exe from HKLM\SYSTEM\CurrentControlSet\Session Manager\BootExecute.
  4. Unmount and commit: reagentc /unmountre /path C:\WinRE /commit
  5. Re-establish BitLocker trust for WinRE: reagentc /enable

Strongly recommended: Switch BitLocker from TPM-only to TPM+PIN mode:

manage-bde -protectors -add C: -TPMAndPIN

For unencrypted devices, enable "Require additional authentication at startup" via Intune or Group Policy and set "Configure TPM startup PIN" to "Require startup PIN with TPM."


← Back to the Security Roundup: Week of May 28, 2026


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther