Microsoft Unveils Mitigations for Windows YellowKey Zero-Day

1 min read
Source: BleepingComputer
Microsoft Unveils Mitigations for Windows YellowKey Zero-Day
Photo: BleepingComputer
TL;DR

Microsoft released mitigations for the YellowKey Windows BitLocker zero-day (CVE-2026-45585) after a PoC disclosure by Nightmare Eclipse, detailing steps to prevent exploitation—removing the autofstx.exe entry from the Session Manager BootExecute to stop FsTx replay, reestablishing BitLocker trust for WinRE, and enforcing TPM+PIN startup or a startup PIN with TPM on devices (via PowerShell, Intune, or Group Policy)—to block attacks until a patch is available.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer