FeedVulnerabilityMicrosoft patches YellowKey, GreenPlasma, MiniPlasma zero-da...
VulnerabilityBleeping Computer
7.8HIGH

Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days

📅 10 June 2026 at 09:57 UTC📰 Bleeping ComputerView original source ↗
Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days

On Tuesday, Microsoft patched two zero-day vulnerabilities that let attackers gain SYSTEM privileges on fully patched Windows systems, and a third one that grants access to BitLocker-protected drives. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Microsoft patched three zero-day vulnerabilities, GreenPlasma and MiniPlasma, which allow local attackers to gain SYSTEM privileges on fully patched Windows systems, and YellowKey, a backdoor in the Windows Recovery Environment that can bypass BitLocker protection.

⚙️Technical Details
CVEs
CVE-2026-45586CVE-2020-17103CVE-2026-45585
Affected Systems
Microsoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 2019Microsoft Windows 11 24H2Microsoft Windows 11 25H2Microsoft Windows 11 26H1Microsoft Windows Server 2025
Attack Vectors
LOCALPHYSICAL
💥Impact Assessment
Severity: CRITICAL
🛡️Recommended Actions
1Apply all available patches from Microsoft's June 2026 Patch Tuesday updates
2Restrict physical access to affected systems
3Monitor system logs for suspicious activity
📦Affected Products
Microsoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 2019Microsoft Windows 11 24H2Microsoft Windows 11 25H2Microsoft Windows 11 26H1Microsoft Windows Server 2025Microsoft Defender Antimalware PlatformMicrosoft Windows
🔐NVD Verified DataVERIFIED
CVE-2026-45586CVSS 7.8HIGH
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-59
CVE-2020-17103CVSS 7HIGH
Attack Vector
LOCAL
Complexity
HIGH
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-269
Affected Products (CPE)
Microsoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 2019
CVE-2026-45585CVSS 6.8MEDIUM
Attack Vector
PHYSICAL
Complexity
LOW
Vector String
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-77
Affected Products (CPE)
Microsoft Windows 11 24H2Microsoft Windows 11 25H2Microsoft Windows 11 26H1Microsoft Windows Server 2025
CVE-2026-33825CVSS 7.8HIGH
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-1220
Affected Products (CPE)
Microsoft Defender Antimalware Platform

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed