CVE-2026-45585
Last modified
CVE-2026-45585 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available. Mitigation FAQs Should I leverage the temporary mitigation? Microsoft recommends that you consider implementing these mitigations if you are concerned your devices and data are at risk of being compromised or stolen. EPSS estimates a 1.25% chance of exploitation in the next 30 days.
Description
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available. Mitigation FAQs Should I leverage the temporary mitigation? Microsoft recommends that you consider implementing these mitigations if you are concerned your devices and data are at risk of being compromised or stolen. For example, if your organization’s employees take their work devices home or on business travel. What impact to service availability/management could be caused by implementing the mitigations? Implementing these mitigations will not impact service availability or management operations. Do customers need to revert the changes made to mitigate the vulnerability once the security update to protect against this vulnerability is available? No. The security update will maintain the mitigation's behavior once the security update is installed. I am using TPM+PIN, am I at risk of this vulnerability being exploited No, if you are using TPM+PIN the vulnerability is not exploitable.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 11 24h2 | All versions |
| Microsoft | Windows 11 25h2 | All versions |
| Microsoft | Windows 11 26h1 | All versions |
| Microsoft | Windows Server 2025 | All versions |
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585Mitigation, Vendor Advisory
- https://github.com/Nightmare-Eclipse/YellowKeyExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-45585?
How severe is CVE-2026-45585?
How do I fix CVE-2026-45585?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4558A flaw has been found in Linksys MR9600 2.0.6.206937. Affect…8.8
- CVE-2026-45580WWBN AVideo is an open source video platform. In 29.0 and ea…5.4
- CVE-2026-45581fabric-chaincode-java is a Java based implementation of Hype…5.5
- CVE-2026-45582n8n-MCP is an MCP server that provides AI assistants access …6.5
- CVE-2026-45583Improper control of generation of code ('code injection') in…8.1
- CVE-2026-45584Heap-based buffer overflow in Microsoft Defender allows an u…8.1
- CVE-2026-45586Improper link resolution before file access ('link following…7.8
- CVE-2026-45588Protection mechanism failure in Windows Secure Boot allows a…7.9
- CVE-2026-45591Uncontrolled resource consumption in ASP.NET Core allows an …7.5
- CVE-2026-45592Integer overflow or wraparound in Windows Internet (wininet.…7.8
- CVE-2026-45593Use after free in Windows SDK allows an authorized attacker …7.8
- CVE-2026-45594Exposure of sensitive information to an unauthorized actor i…5.5
Are you affected by CVE-2026-45585?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
