Microsoft has acknowledged a zero-day vulnerability called YellowKey (CVE-2026-45585) that allows attackers with physical access to a Windows device to bypass BitLocker encryption and read or write files. A public proof of concept already exists. Microsoft issued an advisory with temporary mitigations, primarily focused on restricting physical device access, customizing Secure Boot, and ensuring firmware integrity. Security experts warn that detection is difficult since attacks leave few indicators, and Microsoft's proposed mitigations may be bypassable. A permanent patch is not yet available, and analysts speculate the fix may be complex due to potential design dependencies in Windows.

3m read timeFrom csoonline.com
Post cover image
1 Impression