Executive brief
A security feature bypass vulnerability, known as 'YellowKey,' has been identified in Microsoft Windows. This flaw could allow an individual with physical access to a device to circumvent built-in security protections, potentially leading to unauthorized access to data or system control. While a formal security update is still pending, Microsoft has released mitigation guidance to help organizations protect their systems in the interim.
Technical details
Microsoft Windows is vulnerable to a security feature bypass dubbed 'YellowKey.' The vulnerability is classified as a command injection flaw (CWE-77) that allows for the neutralization of special elements used in commands. According to the CVSS vector (AV:P), the attack requires physical access to the target machine but requires no prior privileges or user interaction. Successful exploitation could result in a total loss of confidentiality, integrity, and availability. A proof of concept has been publicly released, and while a final security patch is not yet available, Microsoft has provided mitigation guidance.
Affected products
- Microsoft Windows
Timeline
- 2026-05-19: disclosed: Vulnerability publicly referred to as YellowKey with public PoC.
- 2026-05-20: advisory: Microsoft issued CVE-2026-45585 with mitigation guidance.