PT-2026-42025 · Microsoft · Windows

Published

2026-05-19

·

Updated

2026-05-20

·

CVE-2026-45585

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows (affected versions not specified)
Description A security feature bypass known as YellowKey allows attackers with physical access to access encrypted data via the Windows Recovery Environment (WinRE).
Recommendations Switch TPM-only BitLocker to TPM+PIN. Remove autofstx.exe from WinRE BootExecute.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-45585

Affected Products

Windows