INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

YellowKey Mitigation Released by Microsoft

| 2026-05-20 15:07 CRITICAL HIGH
Executive Summary AI-generated
Microsoft has issued a YellowKey mitigation, urging admins to disable autofstx.exe and enable TPM+PIN. The flaw affects Windows 11 versions 24H2, 25H2, and 26H1 on x64 systems, as well as Windows Server 2025 in standard and Server Core installations. Microsoft is aware of a security feature bypass vulnerability in YellowKey, which has been publicly disclosed by researcher Chaotic Eclipse. The attack involves physical access to the system, with CVSS score 6.8. To prevent the exploit, administrators must disable autofstx.exe and enable TPM+PIN.
Technical Mitigations AI-generated
* Disable autofstx.exe and enable TPM+PIN: Disable the autofstx.exe component that is responsible for bypassing BitLocker security features, and switch to using TPM+PIN instead. * Mount WinRE image on each affected device: Mount a copy of the Windows Recovery Environment (WinRE) image on each affected device, which will prevent the Transactional NTFS replay from deleting winpeshl.ini. * Modify BootExecute value under Session Manager: Modify the BootExecute value in the system registry hive to remove the autofstx.exe entry, preventing it from starting automatically when the WinRE image launches. * Switch to TPM+PIN for BitLocker decryption: Switch from using TPM-only BitLocker encryption (which decrypts without user input) to using TPM+PIN encryption, which requires a PIN code.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-33825CVE-2026-33825 CVE-2026-45585CVE-2026-45585
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎April 10, 2026
Attackers exploited BlueHammer on April 10, 2026.
‎April 16
Attackers exploited BlueHammer on April 10, 2026.
‎2026/04/20
Threat actors used BlueHammer to target RedSun.
organisation BlueHammer
tactic Privilege Escalation
organisation CVE-2026-33825
organisation LPE
‎2026/05/13
Microsoft released a mitigation for the YellowKey BitLocker vulnerability.
organisation BitLocker
organisation Vulnerability / Encryption
organisation PoC
‎May 20, 2026
Threat actors exploited a YellowKey zero-day exploit in BitLocker encryption.
organisation BitLocker
organisation Vulnerability / Encryption
‎2022/2026
Threat actors exploited a Windows privilege escalation vulnerability in the CTFMON framework on multiple versions of Windows 11 and Server 2022/2026.
infrastructure Windows
tactic T1584.004 - Server
general_metric 11 versions
tactic Privilege Escalation
‎2022/2025
Threat actors exploited a YellowKey zero-day vulnerability in Windows 11 and Server 2022/2025 systems.
infrastructure Windows
tactic T1584.004 - Server
general_metric 11 versions
infrastructure 10 Server
‎2026/05/20
The researchers disclosed two new Windows zero-day vulnerabilities named YellowKey and GreenPlasma, affecting BitLocker and the CTFMON framework.
organisation BitLocker
organisation the FsTx Auto Recovery Utility
organisation WinRE
organisation BootExecute
organisation Modify BootExecute
organisation Tharros
organisation USB
organisation EFI
organisation Nightmare
infrastructure Windows
organisation GreenPlasma
organisation CTFMON
organisation Microsoft
organisation YellowKey
organisation BitLocker Bypass CVE-2026-45585
organisation CVSS
organisation BlueHammer
organisation FsTx
organisation the Windows Recovery Environment
organisation Systems
organisation GreenPlasma Windows Zero-Days
organisation the Windows Collaborative Translation Framework
organisation Microsoft Defender
organisation RedSun
organisation UnDefend
organisation The Transactional NTFS
organisation PIN
organisation Microsoft Intune
organisation Group Policies
organisation Intune
organisation SecurityAffairs
organisation Chaotic Eclipse
organisation Nightmare-Eclipse
organisation GitHub
organisation Reestablish BitLocker
organisation Security Response Center
organisation MSRC
organisation Huntress
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
10
Server
Intelligence Sources