CVE-2026-45585 (YellowKey): BitLocker Bypass via FsTx + WinRE — Physical Access, No Credentials Needed
Technical root cause of YellowKey: bypassing BitLocker full-disk encryption via WinRE transaction replay without knowing user credentials.
CVE-2026-45585
Severity: CVSS 6.8
Status: Physical access BitLocker bypass
Target Component: Windows Recovery Environment (WinRE)
CVE-2026-45585 (CVSS 6.8), publicly known as YellowKey, is a BitLocker security feature bypass disclosed by researcher Chaotic Eclipse (aka Nightmare-Eclipse). Microsoft published a mitigation on May 20, 2026. A public PoC is available. Physical access to the target machine is required — no credentials, no software installation, no network access needed.
Attack Chain
YellowKey abuses a behavioral trust assumption in the Windows Recovery Environment (WinRE):
- Attacker crafts specially constructed FsTx files on a USB drive or EFI partition.
- USB drive is plugged into the target BitLocker-protected Windows system.
- System is rebooted into WinRE (Windows Recovery Environment).
- WinRE's
autofstx.exe(FsTx Auto Recovery Utility) executes automatically via theBootExecuteregistry value. autofstx.exeperforms cross-volume TxF transaction replay, which deleteswinpeshl.ini— the file that normally controls WinRE startup.- With
winpeshl.iniabsent, the attacker holds CTRL during boot to spawn an unrestricted command shell with full access to the decrypted BitLocker volume.
LevelBlue's updated May 22 analysis confirmed YellowKey can be chained with MiniPlasma for a complete "physical access to full domain persistence" attack path: YellowKey bypasses BitLocker to access the decrypted volume, then MiniPlasma escalates from any local account to SYSTEM.
Affected Versions
- Windows 11 version 26H1 for x64-based Systems
- Windows 11 Version 24H2 for x64-based Systems
- Windows 11 Version 25H2 for x64-based Systems
- Windows Server 2025
- Windows Server 2025 (Server Core installation)
Attack Scenarios
Because YellowKey requires only brief physical access and leaves no persistent hardware artifacts, it is viable across: device theft, border device inspections, insider threats, and supply chain exposure.
Remediation
Microsoft's mitigation removes the autofstx.exe entry from the BootExecute registry value in WinRE:
- Mount the WinRE image:
reagentc /mountre /path C:\WinRE - Mount the system registry hive of the mounted WinRE image.
- Remove
autofstx.exefromHKLM\SYSTEM\CurrentControlSet\Session Manager\BootExecute. - Unmount and commit:
reagentc /unmountre /path C:\WinRE /commit - Re-establish BitLocker trust for WinRE:
reagentc /enable
Strongly recommended: Switch BitLocker from TPM-only to TPM+PIN mode:
manage-bde -protectors -add C: -TPMAndPINFor unencrypted devices, enable "Require additional authentication at startup" via Intune or Group Policy and set "Configure TPM startup PIN" to "Require startup PIN with TPM."
← Back to the Security Roundup: Week of May 28, 2026