Command Injection in Microsoft Windows and Windows Server - CVE-2026-45585

 

Command Injection in Microsoft Windows and Windows Server - CVE-2026-45585

Published: May 21, 2026 / Updated: September 4, 2026


Vulnerability identifier: #VU132037
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45585
CWE-ID: CWE-77
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows an attacker to bypass BitLocker security feature.

The vulnerability exists due to insufficient input validation. An attacker with physical access to the system can bypass BitLocker security feature and compromise the affected system.

The vulnerability was dubbed "YellowKey" during public disclosure. 


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2026-45585

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins