Loading...
Loading...
One or more of the following symptoms might be observed: The Microsoft 2023 Secure Boot KEK is not present in UEFI Secure Boot database after applying available Secure Boot updates. Future Secure Boot revocation list (dbx) updates and Secure Boot database (db) (not including 2023 certificates) are not applied. Validation tools indicate the system is missing the Microsoft 2023 KEK.
Windows Secure Boot updates rely on existing KEKs in firmware to authenticate and authorize the installation of newer Secure Boot certificates. These affected systems contain OEM Key Exchange Keys (KEKs) could not be submitted to Microsoft due to platforms reaching End of Service Life, preventing the ability to for Windows to update.
Systems that cannot receive the Microsoft 2023 KEK remain functional and can continue using Secure Boot. They will also receive current 2023 Secure Boot certificate updates. However, over time these systems may experience reduced Secure Boot protection because: Newly revoked bootloaders may continue to be trusted. Known-vulnerable boot components may remain allowed to execute. For example, when Microsoft publishes a dbx update to block a vulnerable bootloader, affected systems may be unable to install the update. In this scenario, the vulnerable bootloader could continue to be trusted by firmware. There is no field update available to enable installation of the Microsoft 2023 KEK on the affected systems. You should: Confirm that your platform is included in the list of affected systems. Continue applying all available BIOS, firmware, and Windows security updates supported by the platform to maintain the highest-level security possible. Evaluate platform replacement plans for impacted systems. Back to Top
Click on a version to see all relevant bugs
Dell Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.