Microsoft June 2026 Patch Tuesday Deep Dive — YellowKey, GreenPlasma, CTFMON EoP & Record 200+ CVEs

Technical deep dive into Microsoft June 2026 Patch Tuesday addressing over 200 CVEs including YellowKey BitLocker bypass.

Microsoft June 2026 Patch Tuesday Deep Dive — YellowKey, GreenPlasma, CTFMON EoP & Record 200+ CVEs
📌
Security Roundup Series: Week of June 12, 2026 • 4 min read deep dive

This post is part of the Week of June 12, 2026 Security Roundup.


Overview

Microsoft's June 2026 Patch Tuesday is the largest in the program's history, surpassing the previous record of 167 CVEs set in October 2025. The release addresses 200+ vulnerabilities across Windows, Office, Exchange, .NET, Azure, and developer tools, with 33 rated Critical. Six zero-days were patched, three of which had been publicly disclosed.

Release date: June 10, 2026
Total CVEs: ~206
Critical: 33 (28 RCE, 4 EoP, 1 info disclosure)
Zero-days patched: 6

Zero-Day Deep Dives

CVE-2026-45585 — YellowKey: BitLocker Bypass via WinRE (CVSS 6.8)

YellowKey is a BitLocker security feature bypass in the Windows Recovery Environment (WinRE) disclosed by researcher Chaotic Eclipse (aka Nightmare-Eclipse). An attacker with brief physical access to a device can:

  1. Boot into WinRE (via repeated forced shutdowns during POST, or by removing the drive and mounting it)
  2. Exploit the FsTx driver interaction with WinRE's pre-boot environment
  3. Bypass BitLocker Device Encryption and access the encrypted volume's contents without the PIN or TPM unlock

Affected: Windows 11 (all versions), Windows Server 2022, Windows Server 2025
Mitigation while patching: Enable BitLocker PIN on all devices (manage-bde -protectors -add C: -TPMAndPIN); this defeats the bypass even on unpatched systems.

CVE-2026-45586 — GreenPlasma: Windows CTFMON EoP to SYSTEM (CVSS 7.8)

GreenPlasma is an elevation of privilege in the Windows Collaborative Translation Framework Monitor (CTFMON), exploiting improper link resolution (link following / CWE-59) in the CTF protocol handler. An attacker with a local shell (any user) can escalate to SYSTEM by creating a crafted symbolic link that CTFMON follows during its privileged cleanup routine.

# Simplified attack concept (not a working exploit):
# 1. Create a symlink at the target path CTFMON resolves during cleanup
mklink /J C:\Windows\System32\CTFLoad_target C:ttacker_dir
# 2. Trigger CTFMON operation (via language bar interaction or scheduled task)
# 3. CTFMON follows the junction with SYSTEM privileges
# 4. Attacker writes to or executes from the target path

CVE-2026-49160 — HTTP.sys HTTP/2 Bomb DoS (CVSS 7.5)

An HTTP/2 Bomb (CONTINUATION flood variant) in Windows HTTP.sys can cause IIS and any other HTTP.sys-backed Windows web service to become unresponsive. A remote, unauthenticated attacker sends a stream of CONTINUATION frames with HPACK-compressed headers that expand to extremely large sizes, exhausting server memory.

# Detection: monitor for HTTP.sys event log errors:
Get-EventLog -LogName System -Source HTTP -EntryType Error | Where-Object {$_.EventID -in @(15010, 15011)} | Select-Object -Last 20

CVE-2026-50507 — MiniPlasma: BitLocker Security Feature Bypass (CVSS 6.8)

MiniPlasma is a second BitLocker bypass disclosed by Chaotic Eclipse, involving the Windows Cloud Files filter driver (cldflt.sys). This is a race condition in the cloud file synchronization layer that, under specific timing conditions, allows an attacker with physical access to extract the BitLocker Volume Master Key (VMK) from memory during a cloud sync operation. Differs from YellowKey in that it requires a running Windows session rather than the WinRE environment.

Critical RCE Highlights

Beyond the zero-days, 28 Critical-rated RCE vulnerabilities were patched this cycle. Key targets:

  • Windows DNS Server — multiple RCE vulnerabilities; domain controllers are at risk
  • Microsoft Exchange Server — two RCE vulnerabilities requiring authentication bypass chain
  • SharePoint — server-side code injection via uploaded files
  • Windows Remote Desktop Services — pre-auth RCE in RDP gateway component

Remediation Commands

# Verify patch installation (PowerShell)
Get-HotFix | Where-Object { $_.InstalledOn -gt (Get-Date).AddDays(-7) } | Sort-Object InstalledOn -Descending

# Check specific KBs for key platforms
$kbs = @{
    "Server 2025" = "KB5060836"
    "Server 2022" = "KB5060842"
    "Server 2019" = "KB5060840"
    "Windows 11 24H2" = "KB5060533"
    "Windows 11 23H2" = "KB5060533"
    "Windows 10 22H2" = "KB5060505"
}
foreach ($os in $kbs.Keys) {
    $kb = $kbs[$os]
    $installed = Get-HotFix -Id $kb -ErrorAction SilentlyContinue
    Write-Host "$os - $kb : $(if ($installed) {'INSTALLED'} else {'MISSING'})"
}

# Enable BitLocker PIN as YellowKey/MiniPlasma mitigation on laptops/mobile devices
manage-bde -protectors -add C: -TPMAndPIN

# Verify BitLocker protectors
manage-bde -protectors -get C:

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther