Three critical vulnerabilities in Windows that require immediate patch and a wave of public leaks

Author: Published 3 min de lectura 172 reading

The images in this article were generated with artificial intelligence. How we publish

Microsoft corrected three critical vulnerabilities on Windows on Tuesday that, combined with the context of public leaks, have turned on alarms between administrators and incident response teams. Two of these failures, baptized in the community as GreenPlasma and MiniPlasma, are steps of local privilege that allow an attacker to obtain a console with SYSTEM permissions in fully parched equipment; the third, known as YellowKey, opens the door to BitLocker protected disk data recovery from the recovery environment (WinRE) if the system is not updated.

From a technical point of view, GreenPlasma affects the collaborative translation service (CTFMON) and MiniPlasma to the Cloud Files Mini Filter controller, both offering vectors to run code with the highest privileges without the need for high credentials. YellowKey, for its part, exploits the logic of the recovery environment to introduce a "bridge" that allows access to encrypted volumes when a combination of conditions is met (including physical access). Microsoft describes the details and updates needed in its official notices, which should be read before you deploy large-scale changes: CVE-2026-45586 and CVE-2026-45585.

Three critical vulnerabilities in Windows that require immediate patch and a wave of public leaks
Image generated with IA.

The real impact is not only technical: the disclosure of these failures occurred after the publication by a researcher known as "Nightmare Eclipse," who has been leaking evidence of concept and exploits for several vulnerabilities as a form of protest for the management of disclosure by the Microsoft Response Center. Public tension led Microsoft to issue warnings about responsible disclosure before nuanced its response. The company's official position on coordinated disclosure is available here: a-share-responsibility-protecting-customers-throughout-coordinated -vulnerability-disclosure.

For managers and users, the first and most urgent recommendation is apply the June 2026 patches immediately following internal test processes. In business environments this involves prioritizing servers and machines with access to sensitive data and domain accounts. In addition, to mitigate YellowKey risks while patches are being deployed, Microsoft and experts recommend reviewing the recovery environment configuration and BitLocker protection policies: activate protection devices that require PIN or multifactor authentication in boot and store the recovery keys in a safe and managed place, for example by Active Directory or Azure AD. The official BitLocker documentation provides practical guidelines on protection and recovery: BitLocker - Microsoft Docs.

Three critical vulnerabilities in Windows that require immediate patch and a wave of public leaks
Image generated with IA.

Not everything can be solved with patches: protection against attacks with physical access requires physical and procedural controls. Ensure the custody of mobile devices and workstations in offices and logistics centres, limit access to the BIOS / UEFI with administrative passwords, enable Secure Boot where possible and audit changes in WinRE configuration. For large organizations, deploy the update through centralized tools such as WSUS, Intune or patch management solutions to control the rollout and reduce exposure windows.

In detection and response, look for commitment indicators associated with local privilege steps and recovery environment manipulation: unusual process creation events with privileges, CTF subsystem modifications, mini-filter installation or modification, and Microsoft Defender handling signals or update policies. It is also prudent to review related vulnerabilities that the researcher has been publishing publicly in recent months, which increases the likelihood of exploitation directed against slow-patching organizations.

Finally, this wave of failures and leaks highlights a strategic lesson: security is not only technical but coordinated. Companies should combine fast patches, hardening critical configurations, policies for the physical protection of assets and agreements with legal and public relations teams that provide for public outreach scenarios. The security community and suppliers also need to improve the channels of interaction to prevent frustration from resulting in disclosures that increase the risk to users.

Coverage

Related

More news on the same subject.