Microsoft issues mitigation advice for the YellowKey BitLocker bypass

Microsoft has published guidance on YellowKey, a recently disclosed BitLocker bypass vulnerability. YellowKey is part of a series of Windows vulnerabilities published by ChaoticEclipse, and drew attention because exploitation is trivial when the attacker has physical access to the machine.

The advisory describes two actions: enabling TPM with PIN for BitLocker, and removing autofstx.exe from the WinRE BootExecute registry value.

What this means for your business

Most organisations treat disk encryption as the answer to a lost or stolen machine, and build their risk assessment on that. When encryption can be bypassed with physical access, the picture changes: a laptop left at an airport is no longer a closed case but potentially a personal data breach with notification duties. Requiring a PIN carries a real usability cost, which makes it a management decision rather than merely a technical setting.

Berigo recommends

  • Enable TPM with PIN on machines that leave the office, starting with executives, sales and frequent travellers.
  • Remove autofstx.exe from the WinRE BootExecute value in line with Microsoft's guidance.
  • Update your lost equipment procedure so it no longer assumes encryption alone closes the case.
  • Factor physical access risk into decisions about what data may be stored locally on a client.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch