Windows Boot Manager revocations for Secure Boot changes - CVE-2023-24932


Buddywh

Member
Local time
9:43 PM
Posts
24
OS
Windows 11 Pro
I'm on Win 11 Ver 22H2 build 22621.1702

I was reading about this and became a bit concerned by how involved it seems to be. But am also left unsure just whether I should do anything or just wait for the changes to roll out, and if I should do something exactly what and when.

The whole topic is covered here, in this link.

As a home user I don't think I'm significantly threatened by the security threat it's fixing, that since it requires physical access to the computer or a level of remote access I think I would have to grant someone. But the fix, as related, sounds like it can go pretty bad if done incorrectly. So, a few questions:

Am I correct in assuming I'm not significantly threatened as a home user with my desktop computer physically secure in my basement?

Will the three updates MS will roll out (I presume in regular updates) to fix this, the last coming sometime in 2024, do the complete fix for me without my involvement?

If there's a 'yes' for both the above questions I think I should then simply ignore this and pretend I never read about it.​

Is it wise, or under what conditions would it be wise, for me to go through the steps aimed at fixing the problem which are laid out in the above linked article sooner?

Honestly, it looks like something meant for IT professionals in support of a managed environment they tend to but it does say in the article that this is appropriate for home users too.

And as a BTW: I do not maintain bootable media in the form of recovery disks or system images. I prefer user file backups with File History and, should the windows installation crash completely, simply do a clean install of Windows using freshly created media made by the Windows Installation Media Creation tool on another computer and then recover user files from File History. I'm not sure if that simplifies things or not, at least in terms of the mechanics of making the 'fix'.
 
Last edited:

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 5800X
    Motherboard
    Asus TUF B550M Gaming-Plus
    Memory
    GSkill 3200, 2x8GB
    Graphics Card(s)
    MSI RX 6800 XT Gaming Z
    Sound Card
    on-board Realtek
    Monitor(s) Displays
    Samsung 144hz
    Screen Resolution
    1440p
    Hard Drives
    Samsung 980 Pro, Samsung 870 Evo, generic PCIe NVME, WD 1TB 2.5" laptop spinner
    PSU
    Corsair RM 650
    Case
    mATX
    Cooling
    BeQuiet 240mm AIO and a bunch of case fans
    Keyboard
    one that clacks softly
    Mouse
    logitech
    Internet Speed
    bunches of bps
    Browser
    Firefox
    Antivirus
    Windows' own
First, my apologies that no one responded to you in ten days. I just happened to come across your post now.

I know that Microsoft makes it a point in their KB to say that both consumers and enterprise customers should take action to address this issue. However, in my personal opinion, this whole issue can be a bit daunting because there are so many issues to be taken into consideration.

But, in your case, I think that we can really greatly simplify this. Most of the complexity in this whole thing revolves around what to do with boot media that is based upon Windows PE or local installations of Windows PE after the mitigations are applied. Because you are not creating full disk images that would require updating of the boot media, applying this update is actually extremely simple. In fact, the hardest part of this whole issue for you would be to simply verify that the update was successfully applied, and that's a piece of cake :-)

Read through the steps below and see if you want to do this. I think that you will find this to be very simple in your case.

1) You have already completed step one. This step is to simply install the latest Windows updates so that you are on build 1702 or later. I see that you are already on build 1702 so this step is done.

2) Open an elevated command prompt. In other words, open it as Administrator. Then run these four commands exactly as shown below:

NOTE: The command that starts with "reg add" is the last command. It's a little bit long so it may wrap onto a second line below, but from "reg add" to the end is all one command.

mountvol q: /S xcopy %systemroot%\System32\SecureBootUpdates\SKUSiPolicy.p7b q:\EFI\Microsoft\Boot mountvol q: /D reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x10 /f

3) Reboot your computer. After rebooting, wait at least five minutes and then reboot a second time.

4) That's it! At this point you are technically done. However, we'll simply verify that the update took place like this:

Right-click on Start and then select Event Viewer. In Event Viewer, expand Windows Logs > System.

On the far right, select Filter Current Log...

Image1.jpg

Where it says <All Event IDs>, type in 1035 and then click on OK .

Image2.jpg

You should see one event. Click on it and it should say Secure Boot DBX update applied successfully.

Image3.jpg

Done!

I hope that this helps.
 

My Computers

System One System Two

  • OS
    Win11 Pro 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    Intel i7-11700K
    Motherboard
    ASUS Prime Z590-A
    Memory
    128GB Crucial Ballistix 3200MHz DRAM
    Graphics Card(s)
    No GPU - CPU graphics only (for now)
    Sound Card
    Realtek (on motherboard)
    Monitor(s) Displays
    HP Envy 32
    Screen Resolution
    2560 x 1440
    Hard Drives
    1 x 1TB NVMe Gen 4 x 4 SSD
    1 x 2TB NVMe Gen 3 x 4 SSD
    2 x 512GB 2.5" SSDs
    2 x 8TB HD
    PSU
    Corsair HX850i
    Case
    Corsair iCue 5000X RGB
    Cooling
    Noctua NH-D15 chromax.black cooler + 10 case fans
    Keyboard
    CODE backlit mechanical keyboard
    Mouse
    Logitech MX Master 3
    Internet Speed
    1Gb Up / 1 Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
    Other Info
    Additional options installed:
    WiFi 6E PCIe adapter
    ASUS ThunderboltEX 4 PCIe adapter
  • Operating System
    Win11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 13x Gen 2
    CPU
    Intel i7-1255U
    Memory
    16 GB
    Graphics card(s)
    Intel Iris Xe Graphics
    Sound Card
    Realtek® ALC3306-CG codec
    Monitor(s) Displays
    13.3-inch IPS Display
    Screen Resolution
    WQXGA (2560 x 1600)
    Hard Drives
    2 TB 4 x 4 NVMe SSD
    PSU
    USB-C / Thunderbolt 4 Power / Charging
    Mouse
    Buttonless Glass Precision Touchpad
    Keyboard
    Backlit, spill resistant keyboard
    Internet Speed
    1Gb Up / 1Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
    Other Info
    WiFi 6e / Bluetooth 5.1 / Facial Recognition / Fingerprint Sensor / ToF (Time of Flight) Human Presence Sensor
Shouldn't this also be included in a Windows Update package?
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 (Build 22631.3296)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom built
    CPU
    Intel i9-9900K
    Motherboard
    Gigabyte Aorus Z390 Xtreme
    Memory
    32G (4x8) DDR4 Corsair RGB Dominator Platinum (3600Mhz)
    Graphics Card(s)
    Radeon VII
    Sound Card
    Onboard (ESS Sabre HiFi using Realtek drivers)
    Monitor(s) Displays
    NEC PA242w (24 inch)
    Screen Resolution
    1920 x 1200
    Hard Drives
    5 Samsung SSD drives: 2X 970 NVME (512 & 1TB), 3X EVO SATA (2X 2TB, 1X 1TB)
    PSU
    EVGA Super Nova I000 G2 (1000 watt)
    Case
    Cooler Master H500M
    Cooling
    Corsair H115i RGB Platinum
    Keyboard
    Logitech Craft
    Mouse
    Logitech MX Master 3
    Internet Speed
    500mb Download. 11mb Upload
    Browser
    Microsoft Edge Chromium
    Antivirus
    Windows Security
    Other Info
    System used for gaming, photography, music, school.
  • Operating System
    Win 10 Pro 22H2 (build 19045.2130)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom Built
    CPU
    Intel i7-7700K
    Motherboard
    Gigabyte GA-Z270X-GAMING 8
    Memory
    32G (4x8) DDR4 Corsair Dominator Platinum (3333Mhz)
    Graphics card(s)
    AMD Radeon R9 Fury
    Sound Card
    Onboard (Creative Sound Blaster certified ZxRi)
    Monitor(s) Displays
    Dell U2415 (24 inch)
    Screen Resolution
    1920 x 1200
    Hard Drives
    3 Samsung SSD drives: 1x 512gig 950 NVMe drive (OS drive), 1 x 512gig 850 Pro, 1x 256gig 840 Pro.
    PSU
    EVGA Super Nova 1000 P2 (1000 watt)
    Case
    Phantek Enthoo Luxe
    Cooling
    Corsair H100i
    Mouse
    Logitech MX Master
    Keyboard
    Logitech MK 710
    Internet Speed
    100MB
    Browser
    Edge Chromium
    Antivirus
    Windows Security
    Other Info
    This is my backup system.
...

But, in your case, I think that we can really greatly simplify this. Most of the complexity in this whole thing revolves around what to do with boot media that is based upon Windows PE or local installations of Windows PE after the mitigations are applied. Because you are not creating full disk images that would require updating of the boot media, applying this update is actually extremely simple. In fact, the hardest part of this whole issue for you would be to simply verify that the update was successfully applied, and that's a piece of cake :-)
...
I think that's the "money line" :) It sounds like even if things go wrong I'm not really going to lose more than a couple hours to reinstall Windows and recover my user files from a file history.

But now the second part of my question... Should I really worry about the threat this is fixing? I AM a home user with my system locked up in a basement. So isn't it a lot easier to just Microsoft do it's thing as they roll out future updates?
 

My Computer

System One

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY
    CPU
    Ryzen 7 5800X
    Motherboard
    Asus TUF B550M Gaming-Plus
    Memory
    GSkill 3200, 2x8GB
    Graphics Card(s)
    MSI RX 6800 XT Gaming Z
    Sound Card
    on-board Realtek
    Monitor(s) Displays
    Samsung 144hz
    Screen Resolution
    1440p
    Hard Drives
    Samsung 980 Pro, Samsung 870 Evo, generic PCIe NVME, WD 1TB 2.5" laptop spinner
    PSU
    Corsair RM 650
    Case
    mATX
    Cooling
    BeQuiet 240mm AIO and a bunch of case fans
    Keyboard
    one that clacks softly
    Mouse
    logitech
    Internet Speed
    bunches of bps
    Browser
    Firefox
    Antivirus
    Windows' own
Back
Top Bottom