Windows 10: Issues with Dell Optiplex after Release KB5025885: Windows Boot Manager revocations for...

Discus and support Issues with Dell Optiplex after Release KB5025885: Windows Boot Manager revocations for... in Windows 10 Installation and Upgrade to solve the problem; Hello all,We have noticed changes in the Bitlocker Event Manager on some Optiplex from Dell after the update release. Several reboots were performed... Discussion in 'Windows 10 Installation and Upgrade' started by Bogdan Guinea, Jun 6, 2024.

  1. Issues with Dell Optiplex after Release KB5025885: Windows Boot Manager revocations for...


    Hello all,We have noticed changes in the Bitlocker Event Manager on some Optiplex from Dell after the update release. Several reboots were performed and the system goes into Bitlocker recovery mode, we also had cases where the boot order was changed. After we started investigating this issue, we found the release based on the Microsoft link see link Microsoft says that this is not enabled by default. see link https://support.microsoft.com/en-us/topic/kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a

    :)
     
    Bogdan Guinea, Jun 6, 2024
    #1

  2. KB5025885: APPLY revocations to protect against the vulnerability in CVE-2023-24932.

    I follow this KB KB5025885: How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932 - Microsoft Support

    After installing the Windows updates released on or after July 11, 2023, open a Command Prompt window running as an Administrator, type the following command and then press Enter:

    reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Secureboot /v AvailableUpdates /t REG_DWORD /d 0x30 /f

    The value of AvailableUpdates, set as REG_DWORD with a value of 0x30 and enforced through either manual resetting or Group Policy Object (GPO), consistently reverts back to its default value of 0. This issue occurs across both Windows 10 and Windows 11 workstations.

    Best regards,
     
    Andy Wong2, Jun 6, 2024
    #2
  3. Using Bcdboot repair after appling Windows Boot Manager revocations for Secure Boot changes

    I already applied applied the Windows Boot Manager revocations for Secure Boot changes referring to this:

    KB5025885: How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932 - Microsoft Support

    My question: I did a disk restore but no boot, so I formatted the fat32 efi partition and using Bcdboot repaired the booting. Which I have done many times as needed over the years.

    But now with the revocations for Secure Boot, does using Bcdboot like I did affect the revocations?

    Note the not booting had nothing to do with the revocations, I restored to a different size drive using Acronis and restored one partition at a time. I have done this before as well.

    I only need to know if Bcdboot affects the revocations.
     
    jimmiewhitaker, Jun 6, 2024
    #3
  4. Issues with Dell Optiplex after Release KB5025885: Windows Boot Manager revocations for...

    Black Lotus Revocation Issue: Should I Be Worried About The Digital Signature Timestamp Difference?

    Hello All I was trying to harden up my Windows 10 Enterprise install and I had what I thought might be a little issue. I was following the instructions for the Black Lotus set of revocations for the my boot manager detailed here When I got to the end of step 2 (part D.: step IV) I checked the digital signatures on bootmgfw_2023.efi and everything was matching what was to be expected from the article except for the date listed in the digital signature page was a little more than 7 days off. This made me worry and I was just wondering if I should be worried and if so, how I should fix the problem. I've tried resyncing my clock but that didn't seem to do anything. I've attached images here for comparison between the image in the article and the picture I took of my laptop when I was at that same step. Thank you Issues with Dell Optiplex after Release KB5025885: Windows Boot Manager revocations for... :).
     
    Snowstorm48562, Jun 6, 2024
    #4
Thema:

Issues with Dell Optiplex after Release KB5025885: Windows Boot Manager revocations for...

Loading...
  1. Issues with Dell Optiplex after Release KB5025885: Windows Boot Manager revocations for... - Similar Threads - Issues Dell Optiplex

  2. Issues with Dell Optiplex after Release KB5025885: Windows Boot Manager revocations for...

    in Windows 10 Gaming
    Issues with Dell Optiplex after Release KB5025885: Windows Boot Manager revocations for...: Hello all,We have noticed changes in the Bitlocker Event Manager on some Optiplex from Dell after the update release. Several reboots were performed and the system goes into Bitlocker recovery mode, we also had cases where the boot order was changed. After we started...
  3. Issues with Dell Optiplex after Release KB5025885: Windows Boot Manager revocations for...

    in Windows 10 Software and Apps
    Issues with Dell Optiplex after Release KB5025885: Windows Boot Manager revocations for...: Hello all,We have noticed changes in the Bitlocker Event Manager on some Optiplex from Dell after the update release. Several reboots were performed and the system goes into Bitlocker recovery mode, we also had cases where the boot order was changed. After we started...
  4. No boot in Dell Optiplex

    in Windows 10 Gaming
    No boot in Dell Optiplex: Desktop won't power on https://answers.microsoft.com/en-us/windows/forum/all/no-boot-in-dell-optiplex/185b9832-deb5-4b88-8c01-54bdf213dde2
  5. Dell Optiplex No Boot

    in Windows 10 Installation and Upgrade
    Dell Optiplex No Boot: Desktop No boot ,Black Screen https://answers.microsoft.com/en-us/windows/forum/all/dell-optiplex-no-boot/68cdd510-b92c-427c-b83c-5796d2cf5e70
  6. No boot in Dell Optiplex

    in Windows 10 BSOD Crashes and Debugging
    No boot in Dell Optiplex: Desktop won't power on https://answers.microsoft.com/en-us/windows/forum/all/no-boot-in-dell-optiplex/185b9832-deb5-4b88-8c01-54bdf213dde2
  7. Dell Optiplex No Boot

    in Windows 10 Gaming
    Dell Optiplex No Boot: Desktop No boot ,Black Screen https://answers.microsoft.com/en-us/windows/forum/all/dell-optiplex-no-boot/68cdd510-b92c-427c-b83c-5796d2cf5e70
  8. Dell Optiplex No Boot

    in Windows 10 Software and Apps
    Dell Optiplex No Boot: Desktop No boot ,Black Screen https://answers.microsoft.com/en-us/windows/forum/all/dell-optiplex-no-boot/68cdd510-b92c-427c-b83c-5796d2cf5e70
  9. KB5025885: How to manage the Windows Boot Manager revocations for Secure Boot changes...

    in Windows 10 Gaming
    KB5025885: How to manage the Windows Boot Manager revocations for Secure Boot changes...: Hi Team,Regarding CVE-2023-24932, As per the below instructions it is not possible to update the bootable media manually for all the machines in an organization, do we have any alternative for this?Please revert back us ASAP, or route us to get the proper support on...
  10. KB5025885: How to manage the Windows Boot Manager revocations for Secure Boot changes...

    in Windows 10 Software and Apps
    KB5025885: How to manage the Windows Boot Manager revocations for Secure Boot changes...: Hi Team,Regarding CVE-2023-24932, As per the below instructions it is not possible to update the bootable media manually for all the machines in an organization, do we have any alternative for this?Please revert back us ASAP, or route us to get the proper support on...