msrc disclosure

  1. YellowKey CVE-2026-45585: BitLocker Bypass via WinRE Physical Access & Microsoft Mitigation

    Microsoft acknowledged CVE-2026-45585 on May 19, 2026, after researcher Nightmare-Eclipse publicly released YellowKey, a proof-of-concept Windows Recovery Environment technique that can bypass BitLocker protections on affected Windows 11 systems with physical access. The company’s response is...