Microsoft patches GreenPlasma, MiniPlasma, YellowKey zero-days
Microsoft fixed three zero-days disclosed by researcher Nightmare Eclipse: two privilege escalation flaws (GreenPlasma, MiniPlasma) granting SYSTEM access and YellowKey enabling BitLocker bypass.
Microsoft released patches for three zero-day vulnerabilities publicly disclosed by security researcher Nightmare Eclipse in protest over MSRC's disclosure handling. CVE-2026-45586 (GreenPlasma) and CVE-2020-17103 (MiniPlasma) are local privilege escalation flaws in the Collaborative Translation Framework and Cloud Files Mini Filter Driver respectively, allowing attackers to obtain SYSTEM-level shells on fully patched Windows systems.
The third vulnerability, CVE-2026-45585 (YellowKey), is a backdoor in the Windows Recovery Environment affecting Windows 11 and Windows Server 2022/2025. Attackers with physical access can exploit YellowKey to bypass BitLocker encryption on unpatched systems. Microsoft provided mitigation guidance while criticizing the public disclosure as violating coordinated vulnerability practices.
These disclosures follow a pattern from Nightmare Eclipse, who previously released exploits for BlueHammer (CVE-2026-33825) and RedSun LPE zero-days now under active exploitation, plus UnDefend and RoguePlanet affecting Microsoft Defender. Microsoft initially threatened legal action but later stated it would work with law enforcement only when researchers engage in malicious activity causing customer harm.
Mentioned in this report
Source reporting: https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-yellowkey-greenplasma-miniplasma-zero-days/
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free