Popular Post psydii Posted May 10, 2023 Popular Post Posted May 10, 2023 Not just servers! After installing 9th May 2023 updates, you will not be able to restore to a bootable state from backups taken before the 9th May update was installed. ...with caveats. Fully applying the update will prevent restoring / booting from older backups. You absolutely have to take the additional steps to have the update protect you from the risk, but you need to be aware that it brings its own risks/problems that need to be managed. Since this update resolves a SecureBoot/EUFI vulnerability, if you have old infrastructure that doesn't have SecureBoot/EUFI this doesn't affect you today... but it will in the future, so I encourage everybody to read the notes! https://support.microsoft.com/en-us/topic/kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d 9
BOOT Posted May 10, 2023 Posted May 10, 2023 I don't see anyone going through the 28 steps involved in manually updating boot\install\recovery\online\pxe media. It's ridiculous.
TwistedHelixis Posted May 10, 2023 Posted May 10, 2023 So, if I use Windows backup to take backups of my Hyper-V vms, In theory, after this update has applied to both the host and VMs, all backups after that should contain the new secure boot info and be restorable / bootable. Its only the backups taken before this months updates that will not be bootable. Is that correct??
Fazza Posted May 10, 2023 Posted May 10, 2023 Sounds like if you have to restore a server from before this update was applied you will need to turn secure boot off in the EUFI/BIOS to allow the OS to load and then there are a list of commands to follow that update the boot area so you can then turn secure boot boot back on. 1
free780 Posted May 10, 2023 Posted May 10, 2023 I don't see anyone going through the 28 steps involved in manually updating boot\install\recovery\online\pxe media. It's ridiculous. You need a compliance item in MECM constantly checking the changes had been done. Shame Microsoft couldn’t just supply that or a scheduled task that ran the command of needed.
PotNoodleTech Posted May 11, 2023 Posted May 11, 2023 I am assuming this doesn't affect Veeam users? (as you would be effectively restoring the entire server in it's pre-9th may state anyway?)
BOOT Posted May 11, 2023 Posted May 11, 2023 As long as you're not performing the additional manual steps to enable the changes, it doesn't seem to affect anything. If you are enabling the changes manually.. anything using secure boot (existing build media, pxe, recovery mode) is broken.
Koldov Posted May 11, 2023 Posted May 11, 2023 This is pretty big... how are we only finding out about this the day after patch Tuesday...? Am I understanding this right...? After I apply the revocations (additional manual steps), the backup I would take before applying such a major change would be useless unless I do all the steps involved in manually updating the recovery media...? "CAUTION After the revocations are applied, bootable media that is not updated will no longer work as expected. Do not proceed with “Step 3: Apply” until you have followed the guidance regarding bootable media." Then to apply the revocations on 1000's of devices, we have to do that manually...? "Open a Command Prompt window running as an Administrator, type each of the following commands and then press Enter to copy the Code Integrity Boot Policy to the devices EFI partition." "After installing the Windows updates released on or after May 9, 2023, open a Command Prompt window running as an Administrator, type the following command and then press Enter:" "Important: An additional restart is required to fully initialize the revocation protections." Like I could even get my lot to restart once a month... Do we just delete all previous ISO files that we have or re-download them/update them somehow? What happens to the average Joe/Jolene consumer who created a back-up (as if) or is relying on their built-in OEM restore partition and doesn't have a clue? Will there be a time when this is all 'automagically' applied? I guess this bit? "NOTE We are working on SafeOS dynamic updates for an upcoming release"
BOOT Posted May 11, 2023 Posted May 11, 2023 May be some automated deployment options for the 'second deployment phase' in the July 2023 updates.
penfold Posted May 12, 2023 Posted May 12, 2023 Question - if you install this update, you are still vulnerable until you perform the addition manual configurations? The way I read it is that this update allow you to update the boot manager but this is not enabled by default. So this leaves you still vulnerable until you perform the manual steps? This will then be enabled automatically during later releases? https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24932
BOOT Posted May 12, 2023 Posted May 12, 2023 Yeah, this update changes the boot manager. It adds a list of revoked certificates for the older compromised boot managers, but doesn't enable it automatically. That's the bit that needs additional manual steps, until they enforce the changes some time in 2024 or sooner. 1
MYK-IT Posted May 12, 2023 Posted May 12, 2023 Some further and clearer information here... https://nakedsecurity.sophos.com/2023/05/10/bootkit-zero-day-fix-is-this-microsofts-most-cautious-patch-ever/ 1
penfold Posted May 12, 2023 Posted May 12, 2023 Yeah, so basically you can patch, but it doesn't remediate the vulnerability until you take the additional steps. So we need to carry out the steps highlighted after patching to ensure we are safe. Otherwise we patch and we are up to date and have "patched" systems, but we are still vulnerable to CVE-2023-24932 - Secure Boot Security Feature Bypass Vulnerability
ITGuyNW Posted May 12, 2023 Posted May 12, 2023 I'm going to wait a couple of months until the safer guidance is out. It seems a bit messy to me.
psydii Posted May 12, 2023 Author Posted May 12, 2023 I'm kind-of expecting/fearful that the Windows 10 ADK/WinPE boot images wont get an update, and remain requiring this messy process to encourage migration to Windows 11.
penfold Posted May 16, 2023 Posted May 16, 2023 (edited) I've just been told that this vulnerability does not affect VMs. Can anyone confirm that this is the case? If I understand this vulnerability it attempts to disable Virtualised based security? - https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/#step-2 According to MS this also impacts some VMs https://support.microsoft.com/en-us/topic/kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d#scopeofimpact5025885 Edited May 16, 2023 by penfold
BOOT Posted May 16, 2023 Posted May 16, 2023 This does affect VMs if your virtualisation hosting supports secure boot and boot certificate revocation. 1
BOOT Posted May 16, 2023 Posted May 16, 2023 If you apply the certificate revocations, none of the current build media will boot. Not even the most recent ISO. Nothing has been released yet that will.
k-strider Posted May 18, 2023 Posted May 18, 2023 Updated build media has been released. i assume that the iso in o365 Admin center for Windows 10 that was realeased yesterday has this in it. Server 2022 is still 24th Aprial
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now