Additional guidance for devices using Secure Boot for CVE-2023-24932

    Additional guidance for devices using Secure Boot for CVE-2023-24932

    Additional guidance for devices using Secure Boot for CVE-2023-24932


    Last Updated: 12 Jul 2023 at 10:46

    UPDATE 7/11:
    Second Deployment This phase starts with updates released on July 11, 2023, which adds additionally support mitigating the issue.

    Security updates released May 9, 2023 and later contain security hardening changes to protect against vulnerabilities tracked by CVE-2023-24932 that can bypass the Secure Boot security feature using the BlackLotus UEFI bootkit. These hardening changes are available but not enabled by default in these updates. The security hardening for CVE-2023-24932 will be done in phases, as steps must be taken to prevent issues on your device when the revocations are applied/enabled, which is required to address CVE-2023-24932.

    For information on how to apply the revocations and what is required before you apply the revocations, see KB5025885: How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932. We recommend that all Windows users review this documentation carefully, including both IT administrators and consumers.

    Read more: https://support.microsoft.com/en-us/...3-b3ff139f832d
    Brink's Avatar Posted By: Brink
    09 May 2023


  1. Posts : 14
    Windows 10-22H2
       #1

    i need help with this. the advisory says to create boot media for installing windows 10 that includes the may 9th windows update and that the ISO's for that will be available through "windows downloads." well, the ISO for creating boot media for installing windows 10 is labeled as "22H2." how can we tell if the ISO for installing windows 10 has been updated to include the may 9th windows update?
      My Computer


  2. Posts : 31,923
    10 Home x64 (22H2) (10 Pro on 2nd pc)
       #2

    redwolfe98 said:
    i need help with this. the advisory says to create boot media for installing windows 10 that includes the may 9th windows update and that the ISO's for that will be available through "windows downloads." well, the ISO for creating boot media for installing windows 10 is labeled as "22H2." how can we tell if the ISO for installing windows 10 has been updated to include the may 9th windows update?
    Use this tutorial to see the details of the ISO. For a Windows 10 ISO, at Step 6 you want to see a ServicePack Build number of 2965 (or higher).

    See Full Details about a Windows 10 ISO file or USB

    If you use Microsoft's Media Creation Tool to make your ISO, then the Windows 10 MCT now makes an ISO for 19045.2965 which is the May 9th release. The Windows 11 MCT has also been updated to the May 9th release, now making an ISO for 22621.1702.
      My Computers


  3. Posts : 14
    Windows 10-22H2
       #3

    thank you very much, bree. and thanks to brink, too, for providing the information about how to use command prompt to determine the build of the install-media.
      My Computer


  4. Posts : 69,397
    64-bit Windows 11 Pro for Workstations
    Thread Starter
       #4

    UPDATE 7/11:
    Second Deployment This phase starts with updates released on July 11, 2023, which adds additionally support mitigating the issue.
      My Computers


  5. Posts : 7,920
    Windows 11 Pro 64 bit
       #5

    Do we know by when MS plans to fix this issue via Windows Update?
      My Computers


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd
All times are GMT -5. The time now is 20:12.
Find Us




Windows 10 Forums