Windows 10: KB5012170 --- secure boot?

Discus and support KB5012170 --- secure boot? in Windows 10 Software and Apps to solve the problem; Hello --- there seems to be much written about this fix/patch but what I don't understand why is MS trying to apply this to old computer that are... Discussion in 'Windows 10 Software and Apps' started by fpefpe, Jan 14, 2023.

  1. fpefpe Win User

    KB5012170 --- secure boot?


    Hello --- there seems to be much written about this fix/patch but what I don't understand why is MS trying to apply this to old computer that are BIOS/MBR units? I just updated an old computer from win7 to win10 22H2 and update tried to apply this patch 2 times and failed --- it does not make sense --- is MS listening?

    :)
     
    fpefpe, Jan 14, 2023
    #1
  2. Blue O Win User

    KB5012170: Security update for Secure Boot DBX: August 9, 2022 - Install error - 0x800f0922

    I've been fighting the same issues all day. KB5012170 fails to install with error 0x800f0922. Looking through C:\Windows\Logs\CBS\CBS.log reveals errors pointing to BitLocker (which is a red herring) and Secure Boot (the real culprit).

    I finally got it to install successfully as follows:

    1. Open a cmd.exe or powershell.exe window running as Administrator

    2. dism.exe /online /cleanup-image /restorehealth

    3. sfc /scannow

    4. Reboot

    5. Manually download the MSU appropriate for your Windows version directly from the Microsoft Update Catalog here: Microsoft Update Catalog

    6. Double click the MSU file to install

    This still didn't work for me, but it did clean up the CBS store and allowed me to successfully install the August 2022 Cumulative Update. However, manually installing KB5012170 still failed with the same error as Windows Update in Settings: 0x800f0922

    Next, I also performed these additional steps:

    7. Reboot into UEFI BIOS

    8. Enabled Secure Boot (it was disabled in my case) => Note: This alone didn't work for me. I also needed to do the next step.

    9. Clear Secure Boot keys (i.e. reset the Secure Boot keys to default factory settings)

    10. Save and exit UEFI BIOS

    After this, I repeated Steps 1-6 above and the KB5012170 MSU package successfully installed.

    Not sure if this will work for everyone, but since KB5012170 updates the Secure Boot Forbidden Signature Database (DBX) in UEFI, clearing the old and potentially stale boot keys and resetting to factory defaults allowed the update to install required changes to DBX.

    Motherboard: Asrock Z87 Extreme6/ac
     
    Blue O, Jan 14, 2023
    #2
  3. grooner Win User
    KB5012170: Security update for Secure Boot DBX: August 9, 2022 - Install error - 0x800f0922

    Its temporarily disabling Secure Boot that's allowed me - and others - to install the update.

    Loading default factory keys is an important step in allowing Secure Boot to be Enabled.

    I'm not sure I would reset them after enabling Secure Boot or understand that doing this removes "old and potentially stale boot keys" - there can either be the factory default keys needed for Windows or custom keys.

    Also the DBX seems to be a forbidden signatures database - something different from the keys.

    Secure Boot keys settings should be changed with care as doing it the wrong way leads to a boot loops on some systems.
     
    grooner, Jan 14, 2023
    #3
  4. Brink Win User

    KB5012170 --- secure boot?

    KB5012170: Security update for Secure Boot DBX: August 9, 2022

    Read more: https://support.microsoft.com/en-us/...8-c42bd211bb15
     
    Brink, Jan 14, 2023
    #4
Thema:

KB5012170 --- secure boot?

Loading...
  1. KB5012170 --- secure boot? - Similar Threads - KB5012170 secure boot

  2. KB5012170 Secure Boothole is already installed.

    in Windows 10 Installation and Upgrade
    KB5012170 Secure Boothole is already installed.: A few months back, KB5012170 was released to fix a vulnerability in Windows Security Feature Bypass in Secure Boot BootHole. We've installed this fix KB via SCCM and Powershell and confirmed that it is actually installed. However, Tenable is still detecting that the device is...
  3. KB5012170 Secure Boothole is already installed.

    in Windows 10 Gaming
    KB5012170 Secure Boothole is already installed.: A few months back, KB5012170 was released to fix a vulnerability in Windows Security Feature Bypass in Secure Boot BootHole. We've installed this fix KB via SCCM and Powershell and confirmed that it is actually installed. However, Tenable is still detecting that the device is...
  4. KB5012170 Secure Boothole is already installed.

    in Windows 10 Software and Apps
    KB5012170 Secure Boothole is already installed.: A few months back, KB5012170 was released to fix a vulnerability in Windows Security Feature Bypass in Secure Boot BootHole. We've installed this fix KB via SCCM and Powershell and confirmed that it is actually installed. However, Tenable is still detecting that the device is...
  5. Security Update KB5012170

    in Windows 10 Gaming
    Security Update KB5012170: Hi,I work for an organisation with BYO laptops. Recently a very high percentage of laptops are installing KB5012170 and after a reboot are prompted with a windows login screen. The problem is - this login screen does not contain the previous logged in user, so if the clients...
  6. Security Update KB5012170

    in Windows 10 Software and Apps
    Security Update KB5012170: Hi,I work for an organisation with BYO laptops. Recently a very high percentage of laptops are installing KB5012170 and after a reboot are prompted with a windows login screen. The problem is - this login screen does not contain the previous logged in user, so if the clients...
  7. Security Update KB5012170

    in Windows Hello & Lockscreen
    Security Update KB5012170: Hi,I work for an organisation with BYO laptops. Recently a very high percentage of laptops are installing KB5012170 and after a reboot are prompted with a windows login screen. The problem is - this login screen does not contain the previous logged in user, so if the clients...
  8. KB5012170 --- secure boot?

    in Windows 10 Gaming
    KB5012170 --- secure boot?: Hello --- there seems to be much written about this fix/patch but what I don't understand why is MS trying to apply this to old computer that are BIOS/MBR units? I just updated an old computer from win7 to win10 22H2 and update tried to apply this patch 2 times and failed ---...
  9. KB5012170 --- secure boot?

    in Windows 10 Installation and Upgrade
    KB5012170 --- secure boot?: Hello --- there seems to be much written about this fix/patch but what I don't understand why is MS trying to apply this to old computer that are BIOS/MBR units? I just updated an old computer from win7 to win10 22H2 and update tried to apply this patch 2 times and failed ---...
  10. KB5012170: Security update for Secure Boot DBX: August 9, 2022 - Install error - 0x800f0922

    in Windows 10 Gaming
    KB5012170: Security update for Secure Boot DBX: August 9, 2022 - Install error - 0x800f0922: It fails installing trough the update tool of windows itself, but also downloaded manually. and started with admin rights. https://answers.microsoft.com/en-us/windows/forum/all/kb5012170-security-update-for-secure-boot-dbx/699b8c9b-6b97-4216-acd4-b86d91bb9cf9