Command Injection in Microsoft Windows and Windows Server - CVE-2026-45585
Published: May 21, 2026 / Updated: September 4, 2026
Vulnerability details
The vulnerability allows an attacker to bypass BitLocker security feature.
The vulnerability exists due to insufficient input validation. An attacker with physical access to the system can bypass BitLocker security feature and compromise the affected system.
The vulnerability was dubbed "YellowKey" during public disclosure.
Affected software
Windows Server
How to mitigate CVE-2026-45585
Links to Public Exploits and PoC-codes
- Exploit #13061 - YellowKey-BitLocker-CVE-2026-45585 (September 4, 2026)
- Exploit #12908 - YellowKey-Bitlocker-CVE-2026-45585 (YellowKey BitLocker CVE-2026-45585 - free BitLocker recovery key extractor and vulnerability tool. Bitlocker yellowkey, yellowkey bitlocker, yellowkey github, cve-2026-45585, yellowkey vulnerability, yellowkey exploit, (August 14, 2026)