Microsoft has published mitigation guidance for a security vulnerability in the Windows 11 Recovery Environment. The flaw, tracked as CVE-2026-45585, allows attackers to bypass BitLocker encryption using a USB stick and an FsTx folder within WinRE.
Researcher Nightmare-Eclipse accused of violating coordinated vulnerability disclosure best practices after releasing proof-of-concept exploit YellowKey
A researcher known as Nightmare-Eclipse released a proof-of-concept exploit named YellowKey to demonstrate the vulnerability. Microsoft provided a script acting as an interim security fix that removes autofstx.exe from the BootExecute registry value to reduce the attack surface. The script mounts the WinRE image, edits its offline SYSTEM registry to remove the entry if present, and safely commits changes while re-sealing WinRE so BitLocker trust remains intact.
Microsoft stated the public release of the proof-of-concept violated coordinated vulnerability disclosure best practices. The researcher accused Microsoft of defamation and claimed the company revoked access to his MSRC account without explanation. Microsoft leadership did not respond to multiple requests for clarification regarding the account removal.
The conflict highlights tensions between security researchers and software vendors over disclosure timelines and public accountability. Microsoft continues to advise users to apply the mitigation script until a permanent patch becomes available.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.