VulnerabilityBleeping Computer
7.8 — HIGH
Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
On Tuesday, Microsoft patched two zero-day vulnerabilities that let attackers gain SYSTEM privileges on fully patched Windows systems, and a third one that grants access to BitLocker-protected drives. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Microsoft patched three zero-day vulnerabilities, GreenPlasma and MiniPlasma, which allow local attackers to gain SYSTEM privileges on fully patched Windows systems, and YellowKey, a backdoor in the Windows Recovery Environment that can bypass BitLocker protection.
⚙️Technical Details
CVEs
CVE-2026-45586CVE-2020-17103CVE-2026-45585
Affected Systems
Microsoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 2019Microsoft Windows 11 24H2Microsoft Windows 11 25H2Microsoft Windows 11 26H1Microsoft Windows Server 2025
Attack Vectors
LOCALPHYSICAL
💥Impact Assessment
Severity: CRITICAL
🛡️Recommended Actions
1Apply all available patches from Microsoft's June 2026 Patch Tuesday updates
2Restrict physical access to affected systems
3Monitor system logs for suspicious activity
📦Affected Products
Microsoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 2019Microsoft Windows 11 24H2Microsoft Windows 11 25H2Microsoft Windows 11 26H1Microsoft Windows Server 2025Microsoft Defender Antimalware PlatformMicrosoft Windows
🔐NVD Verified DataVERIFIED
CVE-2026-45586 ↗CVSS 7.8 — HIGH
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-59
CVE-2020-17103 ↗CVSS 7 — HIGH
Attack Vector
LOCAL
Complexity
HIGH
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-269
Affected Products (CPE)
Microsoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 2019
CVE-2026-45585 ↗CVSS 6.8 — MEDIUM
Attack Vector
PHYSICAL
Complexity
LOW
Vector String
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-77
Affected Products (CPE)
Microsoft Windows 11 24H2Microsoft Windows 11 25H2Microsoft Windows 11 26H1Microsoft Windows Server 2025
CVE-2026-33825 ↗CVSS 7.8 — HIGH
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-1220
Affected Products (CPE)
Microsoft Defender Antimalware Platform
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
