Microsoft has published mitigations is for a new BitLocker bypass technique that being publicly released as “ YellowKey ” and tracked as CVE-2026-45585 . This is a security feature bypass , not a cryptographic “break”: the problem concerns how the Windows Recovery Environment (WinRE) can be exploited to gain access to BitLocker-protected disk data , under certain conditions.

What is YellowKey?
The attack, as described, is based on placing specially crafted “FsTx” files on a USB drive and/or the EFI partition, rebooting into WinRE , and activating an unrestricted shell (reportedly done by holding down CTRL), which gives access to the storage space.
So, unlike remote exploits, here the risk "enters" from physical access (theft/loss of laptop, access to an office, access to an endpoint while traveling). However, for organizations that handle sensitive data, this is exactly the scenario that BitLocker is called upon to cover.
See also: MiniPlasma: New Windows zero-day worries admins
What Microsoft suggests as an immediate defense
Because there is no full security update yet, Microsoft is providing mitigation instructions that aim to prevent the FsTx Auto Recovery Utility (autofstx.exe) from automatically running when the WinRE image is opened. The recommended approach involves removing the autofstx.exe value from BootExecute (REG_MULTI_SZ) and then restoring/reestablishing trust of BitLocker for WinRE, a process that is referenced in a related advisory.
As described by other sources, the steps for mitigation in summary are:
– Mount WinRE image,
– load registry hive,
– change Session Manager BootExecute (remove autofstx.exe),
– commit/unmount,
– reestablish BitLocker trust for WinRE.

Alternative (and simpler) defense: TPM+PIN
Microsoft also recommends that organizations move from BitLocker “TPM-only” to “TPM+PIN,” requiring a pre-boot PIN to unlock the decryption key at boot. Simply put: even if someone has the device in their hands, TPM alone isn’t enough, a PIN is also needed.
For endpoints that are not yet encrypted, we recommend the “Require additional authentication at startup” policy (Intune/Group Policy) and setting “Configure TPM startup PIN” to “Require startup PIN with TPM”.
See also: Windows systems may experience BitLocker recovery after October 2025 updates
What should IT admins practically do?
1) Take inventory of which endpoints are BitLocker TPM-only
– high-risk laptops (C-level, admins, mobile workers) first.
2) Put TPM+PIN where possible
– it will have a small operational cost (PIN at startup), but significantly increases the difficulty for a physical attacker.
3) Restrict booting from USB/external media and harden UEFI
– active Secure Boot, strong UEFI password, disable external boot options where possible.
4) If you implement WinRE mitigation, organize rollout properly
– it is a process that touches recovery images and registry hives: it requires change management, testing, backup and rollback.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: BitLocker: Automatic encryption can lock your data

What does it mean for Greece/businesses/admins/users?
For Greek businesses and government organizations that rely on BitLocker as a baseline for mobile device protection, YellowKey reminds us that physical access scenarios remain critical: laptop theft, loss while traveling, or access to a workplace. For IT admins in Greece, the practical move today is to evaluate BitLocker policies (TPM-only vs TPM+PIN), check WinRE posture, and restrict external boot.
Source: Bleeping Computer
