Microsoft Unveils Mitigations for Windows YellowKey Zero-Day

TL;DR
Microsoft released mitigations for the YellowKey Windows BitLocker zero-day (CVE-2026-45585) after a PoC disclosure by Nightmare Eclipse, detailing steps to prevent exploitation—removing the autofstx.exe entry from the Session Manager BootExecute to stop FsTx replay, reestablishing BitLocker trust for WinRE, and enforcing TPM+PIN startup or a startup PIN with TPM on devices (via PowerShell, Intune, or Group Policy)—to block attacks until a patch is available.
- Microsoft shares mitigation for YellowKey Windows zero-day BleepingComputer
- Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit The Hacker News
- Windows Zero-Day Barrage Continues After Patch Tuesday Dark Reading
- Nightmare-Eclipse: six zero-days, six weeks and one big grudge Barracuda Networks Blog
- Microsoft Releases Mitigation for Windows BitLocker Security Bypass 0-Day Vulnerability CyberSecurityNews
Want the full story? Read the original reporting
Read on BleepingComputer