Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available.
| Vendor | Product | Versions |
|---|---|---|
| microsoft | windows 11 version 24h2 | -, -, -, -, - |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| microsoft | microsoft windows | cert_advisory | 90% |
Added a new tag 'multiple vulnerabilities' and updated patch availability to null.
Updated affected versions to include Windows 11 Version 25H2 and 26H1, changed severity to HIGH, added new CWE-274, and included new tags related to the vulnerability.
Updated description with more technical detail and clarified that the patch is not yet available.
Updated description with technical details on exploitation and mitigations, added affected versions, and clarified patch availability.
Updated severity to CRITICAL, added affected versions 11 25H2 and 11 26H1, marked exploit as available, and noted that the vulnerability is actively exploited.
Initial creation