Microsoft issues mitigation advice for the YellowKey BitLocker bypass
Microsoft has published guidance on YellowKey, a recently disclosed BitLocker bypass vulnerability. YellowKey is part of a series of Windows vulnerabilities published by ChaoticEclipse, and drew attention because exploitation is trivial when the attacker has physical access to the machine.
The advisory describes two actions: enabling TPM with PIN for BitLocker, and removing autofstx.exe from the WinRE BootExecute registry value.
What this means for your business
Most organisations treat disk encryption as the answer to a lost or stolen machine, and build their risk assessment on that. When encryption can be bypassed with physical access, the picture changes: a laptop left at an airport is no longer a closed case but potentially a personal data breach with notification duties. Requiring a PIN carries a real usability cost, which makes it a management decision rather than merely a technical setting.
Berigo recommends
- Enable TPM with PIN on machines that leave the office, starting with executives, sales and frequent travellers.
- Remove autofstx.exe from the WinRE BootExecute value in line with Microsoft's guidance.
- Update your lost equipment procedure so it no longer assumes encryption alone closes the case.
- Factor physical access risk into decisions about what data may be stored locally on a client.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch