Junglewise Threat Intelligence

CVE-2026-45585: Microsoft Windows security feature bypass in YellowKey

CVE-2026-45585 · Severity: medium · CVSS 6.8 · Published 2026-05-20

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security feature bypass vulnerability, known as 'YellowKey,' has been identified in Microsoft Windows. This flaw could allow an individual with physical access to a device to circumvent built-in security protections, potentially leading to unauthorized access to data or system control. While a formal security update is still pending, Microsoft has released mitigation guidance to help organizations protect their systems in the interim.

Technical details

Microsoft Windows is vulnerable to a security feature bypass dubbed 'YellowKey.' The vulnerability is classified as a command injection flaw (CWE-77) that allows for the neutralization of special elements used in commands. According to the CVSS vector (AV:P), the attack requires physical access to the target machine but requires no prior privileges or user interaction. Successful exploitation could result in a total loss of confidentiality, integrity, and availability. A proof of concept has been publicly released, and while a final security patch is not yet available, Microsoft has provided mitigation guidance.

Affected products

  • Microsoft Windows

Timeline

  • 2026-05-19: disclosed: Vulnerability publicly referred to as YellowKey with public PoC.
  • 2026-05-20: advisory: Microsoft issued CVE-2026-45585 with mitigation guidance.

References