Jump to content

Recommended Posts

Posted
I don't see anyone going through the 28 steps involved in manually updating boot\install\recovery\online\pxe media. It's ridiculous.
Posted

So, if I use Windows backup to take backups of my Hyper-V vms, In theory, after this update has applied to both the host and VMs, all backups after that should contain the new secure boot info and be restorable / bootable.

 

Its only the backups taken before this months updates that will not be bootable.

 

Is that correct??

Posted
Sounds like if you have to restore a server from before this update was applied you will need to turn secure boot off in the EUFI/BIOS to allow the OS to load and then there are a list of commands to follow that update the boot area so you can then turn secure boot boot back on.
  • Thanks 1
Posted
I don't see anyone going through the 28 steps involved in manually updating boot\install\recovery\online\pxe media. It's ridiculous.

 

You need a compliance item in MECM constantly checking the changes had been done. Shame Microsoft couldn’t just supply that or a scheduled task that ran the command of needed.

Posted
As long as you're not performing the additional manual steps to enable the changes, it doesn't seem to affect anything. If you are enabling the changes manually.. anything using secure boot (existing build media, pxe, recovery mode) is broken.
Posted

This is pretty big... how are we only finding out about this the day after patch Tuesday...?

 

Am I understanding this right...? After I apply the revocations (additional manual steps), the backup I would take before applying such a major change would be useless unless I do all the steps involved in manually updating the recovery media...?

 

"CAUTION After the revocations are applied, bootable media that is not updated will no longer work as expected. Do not proceed with “Step 3: Apply” until you have followed the guidance regarding bootable media."

 

Then to apply the revocations on 1000's of devices, we have to do that manually...?

 

"Open a Command Prompt window running as an Administrator, type each of the following commands and then press Enter to copy the Code Integrity Boot Policy to the devices EFI partition."

 

"After installing the Windows updates released on or after May 9, 2023, open a Command Prompt window running as an Administrator, type the following command and then press Enter:"

 

"Important: An additional restart is required to fully initialize the revocation protections."

 

Like I could even get my lot to restart once a month...

 

Do we just delete all previous ISO files that we have or re-download them/update them somehow?

 

What happens to the average Joe/Jolene consumer who created a back-up (as if) or is relying on their built-in OEM restore partition and doesn't have a clue?

 

Will there be a time when this is all 'automagically' applied?

 

I guess this bit? "NOTE We are working on SafeOS dynamic updates for an upcoming release"

Posted

Question - if you install this update, you are still vulnerable until you perform the addition manual configurations? The way I read it is that this update allow you to update the boot manager but this is not enabled by default. So this leaves you still vulnerable until you perform the manual steps? This will then be enabled automatically during later releases?

 

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24932

Posted

Yeah, this update changes the boot manager.

It adds a list of revoked certificates for the older compromised boot managers, but doesn't enable it automatically.

That's the bit that needs additional manual steps, until they enforce the changes some time in 2024 or sooner.

  • Thanks 1
Posted
Yeah, so basically you can patch, but it doesn't remediate the vulnerability until you take the additional steps. So we need to carry out the steps highlighted after patching to ensure we are safe. Otherwise we patch and we are up to date and have "patched" systems, but we are still vulnerable to CVE-2023-24932 - Secure Boot Security Feature Bypass Vulnerability
Posted
I'm kind-of expecting/fearful that the Windows 10 ADK/WinPE boot images wont get an update, and remain requiring this messy process to encourage migration to Windows 11.
Posted (edited)

I've just been told that this vulnerability does not affect VMs. Can anyone confirm that this is the case? If I understand this vulnerability it attempts to disable Virtualised based security? - https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/#step-2

 

According to MS this also impacts some VMs https://support.microsoft.com/en-us/topic/kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d#scopeofimpact5025885

Edited by penfold
Posted
This does affect VMs if your virtualisation hosting supports secure boot and boot certificate revocation.
  • Thanks 1
Posted
If you apply the certificate revocations, none of the current build media will boot. Not even the most recent ISO. Nothing has been released yet that will.
Posted
Updated build media has been released.

i assume that the iso in o365 Admin center for Windows 10 that was realeased yesterday has this in it. Server 2022 is still 24th Aprial

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...