Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
Microsoft fixed three zero-days affecting Windows, including two that can grant SYSTEM privileges and one that can expose BitLocker-protected drives.
Intelligence analysis by GPT-5.4 Mini

Microsoft’s June 2026 Patch Tuesday addresses three publicly disclosed Windows zero-days: GreenPlasma, MiniPlasma, and YellowKey. Two of them enable local privilege escalation to SYSTEM, while the third can let an attacker with physical access bypass BitLocker protections on some unpatched systems.
Microsoft patched three Windows holes. Two could let a local attacker take full control like getting the master key, and one could help someone get past a locked laptop if they had it in their hands.
Analysis
What Microsoft fixed
Microsoft patched three Windows zero-days in its June 2026 Patch Tuesday release. Two of them, tracked as CVE-2026-45586 and CVE-2020-17103 and nicknamed GreenPlasma and MiniPlasma, affect the Collaborative Translation Framework and the Cloud Files Mini Filter Driver. According to the article, local attackers could use them to obtain a shell with SYSTEM privileges on fully patched Windows systems.
The third issue, CVE-2026-45585 or YellowKey, affects the Windows Recovery Environment. The article says it acts like a backdoor in WinRE and could let an attacker with physical access bypass BitLocker protection on unpatched Windows 11 and Windows Server 2022/2025 devices.
Dispute around disclosure
The vulnerabilities were disclosed last month by a researcher using the handle Nightmare Eclipse, who said the release was a protest over Microsoft Security Response Center disclosure handling. Microsoft published mitigation guidance for YellowKey and complained that the proof-of-concept was made public in a way that violated coordinated disclosure best practices.
Broader pattern
The story also places these flaws in a larger run of leaks from the same researcher. The article says prior proof-of-concepts for BlueHammer and RedSun are now actively exploited, and that another leak, UnDefend, can block Microsoft Defender definition updates. More recently, a separate Defender-related exploit named RoguePlanet was disclosed soon after patch release. The overall picture is a fast-moving cycle: public exploit release, emergency attention, and rapid vendor response.
Key points
- Microsoft patched three Windows zero-days in its June 2026 Patch Tuesday.
- GreenPlasma and MiniPlasma can let local attackers reach SYSTEM privileges.
- YellowKey affects WinRE and may allow BitLocker bypass with physical access.
- The flaws were disclosed publicly by a researcher protesting Microsoft’s disclosure process.
- Microsoft also provided mitigation steps for YellowKey.
If administrators apply the June 2026 updates quickly, the affected Windows systems should be protected from these known paths to full control and BitLocker bypass. Microsoft’s mitigation guidance for YellowKey may also help reduce risk while patches roll out.
If systems stay unpatched, local attackers could use the privilege-escalation bugs to reach `SYSTEM` access, which is the highest level on Windows. Devices with physical access may remain exposed to BitLocker bypass attempts on vulnerable versions until the fixes are installed.



