Windows 10: "Microsoft guidance for applying Secure Boot DBX update" "boothole" "nessus scan" "none...

Discus and support "Microsoft guidance for applying Secure Boot DBX update" "boothole" "nessus scan" "none... in AntiVirus, Firewalls and System Security to solve the problem; I followedMicrosoft guidance for applying Secure Boot DBX updateAll seemed well but nessus scan says" The Windows Secure Boot forbidden signature... Discussion in 'AntiVirus, Firewalls and System Security' started by PaulJohnson4535, Jul 3, 2021.

  1. "Microsoft guidance for applying Secure Boot DBX update" "boothole" "nessus scan" "none...


    I followedMicrosoft guidance for applying Secure Boot DBX updateAll seemed well but nessus scan says" The Windows Secure Boot forbidden signature database DBX did not contain the expected certificates. When performing DBX updates exactly as illustrated in the vendor documentation, it is important to note that you are applying only the latest update. Updates applied in this manner may only appended to the DB, so you may still need to apply the older updates from the "Archive of Prior Versions of DBX Files" linked in the UEFI Revocation List File document linked in the See Also advisory. Ple

    :)
     
    PaulJohnson4535, Jul 3, 2021
    #1
  2. CxA2016 Win User

    Microsoft guidance for applying Secure Boot DBX update (ADV 200011) does not work.

    Microsoft guidance for applying Secure Boot DBX update (ADV 200011) does not work.

    Source: Microsoft guidance for applying Secure Boot DBX update

    The description under step 3 seems to be incorrect:

    Set-SecureBootUefi -Name dbx -ContentFilePath .\content.bin -SignedFilePath .\signature.p7 -Time 2010-03-06T19:17:21Z -AppendWrite'

    It also does not describe how to determine again whether the problem has been fixed. When I re-check the changes using the following CmdLet, I always get a "true" result.

    [System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Microsoft Corporation UEFI CA 2011'

    Is the CommandLet in step 3 only an example? Which time stamp (-Time) do I have to use?

    Steps 1-2 worked correctly.

    Best regards
     
    CxA2016, Jul 3, 2021
    #2
  3. z080236 Win User
    Windows Boothole vulnerability - how to verify if it is fixed

    Boothole vulnerability

    BootHole vulnerability in Secure Boot affecting Linux and Windows


    Windows has recently released a patch for the boothole vulnerability

    https://support.microsoft.com/en-us/...7-d0c32ead81e2


    Based on the https://msrc.microsoft.com/update-gu.../CVE-2020-0689

    For Windows server 2016
    I installed the update based on this:
    1. Servicing Stack Update KB4576750
    2. Standalone Secure Boot Update Listed in this CVE KB4535680
    3. Jan 2021 Security Update KB4598243


    Based on https://msrc.microsoft.com/update-gu...lity/ADV200011
    I just run this command to verify?

    [System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Microsoft Corporation UEFI CA 2011'
     
    z080236, Jul 3, 2021
    #3
  4. Brink Win User

    "Microsoft guidance for applying Secure Boot DBX update" "boothole" "nessus scan" "none...

    KB4535680 Security update for Secure Boot DBX - Jan. 12

    Source: https://support.microsoft.com/en-us/...ecure-boot-dbx
     
    Brink, Jul 3, 2021
    #4
Thema:

"Microsoft guidance for applying Secure Boot DBX update" "boothole" "nessus scan" "none...

Loading...
  1. "Microsoft guidance for applying Secure Boot DBX update" "boothole" "nessus scan" "none... - Similar Threads - Microsoft guidance applying

  2. Secure Boot DBX update KB4575994

    in Windows 10 Gaming
    Secure Boot DBX update KB4575994: Good day, questions about Microsoft guidance for applying Secure Boot DBX update KB4575994https://support.microsoft.com/en-us/topic/microsoft-guidance-for-applying-secure-boot-dbx-update-kb4575994-e3b9e4cb-a330-b3ba-a602-15083965d9caContext say that Microsoft will be...
  3. Secure Boot DBX update KB4575994

    in Windows 10 Software and Apps
    Secure Boot DBX update KB4575994: Good day, questions about Microsoft guidance for applying Secure Boot DBX update KB4575994https://support.microsoft.com/en-us/topic/microsoft-guidance-for-applying-secure-boot-dbx-update-kb4575994-e3b9e4cb-a330-b3ba-a602-15083965d9caContext say that Microsoft will be...
  4. Secure Boot DBX update KB4575994

    in AntiVirus, Firewalls and System Security
    Secure Boot DBX update KB4575994: Good day, questions about Microsoft guidance for applying Secure Boot DBX update KB4575994https://support.microsoft.com/en-us/topic/microsoft-guidance-for-applying-secure-boot-dbx-update-kb4575994-e3b9e4cb-a330-b3ba-a602-15083965d9caContext say that Microsoft will be...
  5. Issue with Secure Boot DBX update KB4575994

    in Windows 10 Gaming
    Issue with Secure Boot DBX update KB4575994: I am currently not able to get the command to load the content.bin file. Based on the error, the cmdlet helps suggests there is something wrong with the signature file. I have downloaded all three from https://uefi.org/revocationlistfile.PS C:\temp\BootHole>...
  6. Issue with Secure Boot DBX update KB4575994

    in AntiVirus, Firewalls and System Security
    Issue with Secure Boot DBX update KB4575994: I am currently not able to get the command to load the content.bin file. Based on the error, the cmdlet helps suggests there is something wrong with the signature file. I have downloaded all three from https://uefi.org/revocationlistfile.PS C:\temp\BootHole>...
  7. Issue with Secure Boot DBX update KB4575994

    in Windows 10 Software and Apps
    Issue with Secure Boot DBX update KB4575994: I am currently not able to get the command to load the content.bin file. Based on the error, the cmdlet helps suggests there is something wrong with the signature file. I have downloaded all three from https://uefi.org/revocationlistfile.PS C:\temp\BootHole>...
  8. Apply Windows Security Feature Bypass in Secure Boot BootHole

    in AntiVirus, Firewalls and System Security
    Apply Windows Security Feature Bypass in Secure Boot BootHole: Hello all!I have been attempting to patch some vulnerabilities on our network and have been experiencing some issues and was wondering if anyone had the insight to assist!When running this Powershell command, the result comes back as...
  9. Security update for Secure Boot DBX

    in Windows 10 Installation and Upgrade
    Security update for Secure Boot DBX: Hello All, I am writing this to know What is latest Security update for Secure Boot DBX for Windows 10 Version 20H2 for x64-based Systems and Windows 10 Version 2004 for x64-based Systems, and when latest update will release? Thank you...
  10. Microsoft guidance for applying Secure Boot DBX update ADV 200011 does not work.

    in AntiVirus, Firewalls and System Security
    Microsoft guidance for applying Secure Boot DBX update ADV 200011 does not work.: Microsoft guidance for applying Secure Boot DBX update ADV 200011 does not work. Source: Microsoft guidance for applying Secure Boot DBX update The description under step 3 seems to be incorrect: Set-SecureBootUefi -Name dbx -ContentFilePath .\content.bin...

Users found this page by searching for:

  1. windows 2019 dbx