Windows 10: Windows Boot Issues after MS Security Patches applied

Discus and support Windows Boot Issues after MS Security Patches applied in Windows 10 Installation and Upgrade to solve the problem; We have a strange issue that seems to occur after security updates are applied from Microsoft - but we are not 100% convinced it is a Microsoft issue.... Discussion in 'Windows 10 Installation and Upgrade' started by AndyBain1, Jan 28, 2019.

  1. AndyBain1 Win User

    Windows Boot Issues after MS Security Patches applied


    We have a strange issue that seems to occur after security updates are applied from Microsoft - but we are not 100% convinced it is a Microsoft issue. Apologies for the long post but I wanted to provide as much detail as possible.


    Our laptops are all HP 840 Elitebooks (G1 through to G5) running Windows 10 Enterprise version 1803, all laptops have bitlocker enabled. The problem only affects a certain number of laptops and we've not found a common pattern yet.


    Problem

    - Windows automatic updates take place and includes a security update

    - User shuts their laptop down at the end of the working day

    - The following morning when trying to boot, the laptop gets stuck at the "HP Sure Start" screen and doesn't boot

    - We switch the laptop off and on a few times to force automatic repair and then boot to safe mode

    - We perform a standard reboot and everything works (on occasions we have to remove the security update but that's only on 1 in 10 laptops)


    If this was a HP Sure Start issue then we wouldn't expect it to boot to safe mode so we can only assume that something at the start of the boot up of Windows is causing the problem and, by using Safe Mode, it is allowing us to boot properly and, my theory, is that the security update may have needed a reboot and can finally apply correctly when there are no other programs interfering/blocking it.


    The programs we load that could be contributing to the problem are:


    - Cisco Umbrella

    - Carbon Black

    - Cylance

    - Connected MX

    - CheckPoint VPN Client

    - Ivanti Landesk


    Our vendors have not found anything to suggest it is their software causing the problem but the top 3 in the list above are security products and do not load in Safe Mode so if it is anything causing it, it may be one of them. Windows Event logs do not show anything to suggest the cause of the issue.


    We cannot reproduce the issue at will because once the laptop is working again, it won't fail again. We did try removing the last security update, rebooting, running Windows update manually (which then re-applies that security update). In theory, we should now be able to reboot and reproduce the issue but it boots normally.


    The problem is that if we wait until the monthly patch Tuesday for the next updates, then it means we can only troubleshoot once a month so that approach won't work. I'm hoping for some other suggestions that can help us get to to the bottom of this issue without us disabling too many programs that then make our IT security department nervous.


    Thanks in advance


    Andy

    :)
     
    AndyBain1, Jan 28, 2019
    #1
  2. newtekie1 Win User

    Windows 8 Secure Boot Feature: Not So Secure?

    • Linux
    • Linux
    • Linux
    • Linux
    • Oh and OSX
    Here is a statement from a Kernal Developer at Red Hat:

    I'm not sure this exploits the legacy BIOS but rather it exploits the legacy boot method on MBR drives, injecting a signed key before the OS boots, which you are correct in that it has nothing to do with Windows 8. And the simplest fix would just be to require boot drives use GPT when Secure Boot is enabled in UEFI.
     
    newtekie1, Jan 28, 2019
    #2
  3. Windows 8 Secure Boot Feature: Not So Secure?

    So Linux is switching to secure boot also? Or they have to because of UEFI?
     
    Damn_Smooth, Jan 28, 2019
    #3
  4. suraswami Win User

    Windows Boot Issues after MS Security Patches applied

    MS IE Vulnerability patch failure

    http://support.microsoft.com/kb/2964358


    Known issues with this security update
    • Internet Explorer will crash if you try to install this security update on a Windows 7-based system that does not already have security update 2929437 installed. To avoid this issue, take either of the following actions:
      • Install security update 2929437, and then install security update 2964358. For more information about security update 2929437, click the following article number to view the article in the Microsoft Knowledge Base:
        2929437
        (http://support.microsoft.com/kb/2929437/ )
        Description of the security update for Internet Explorer 11 on Windows 7 and Windows Server 2008 R2: April 8, 2014
      • Install security update 2964444 instead of security update 2964358. Security update 2964444 is intended for systems that do not have security update 2929437 installed.
     
    suraswami, Jan 28, 2019
    #4
Thema:

Windows Boot Issues after MS Security Patches applied

Loading...
  1. Windows Boot Issues after MS Security Patches applied - Similar Threads - Boot Issues Security

  2. Microsoft patches several critical security issues on the May 2023 Windows Patch Day

    in Windows 10 News
    Microsoft patches several critical security issues on the May 2023 Windows Patch Day: Microsoft released security updates and non-security updates for all supported versions of its Windows operating system and other company products on the May 2023 Patch Tuesday. All versions of Windows are affected by critical updates. Updates were also released for other...
  3. Time to Patch: Microsoft released security patch for actively exploited issue

    in Windows 10 News
    Time to Patch: Microsoft released security patch for actively exploited issue: Microsoft released security updates for Windows yesterday on the March 2023 Patch Day. Among the patched security updates, several of which are rated critical by Microsoft, is a security issue that is exploited actively in the wild. The issue was reported by Google's Threat...
  4. Apply Windows Security Feature Bypass in Secure Boot BootHole

    in AntiVirus, Firewalls and System Security
    Apply Windows Security Feature Bypass in Secure Boot BootHole: Hello all!I have been attempting to patch some vulnerabilities on our network and have been experiencing some issues and was wondering if anyone had the insight to assist!When running this Powershell command, the result comes back as...
  5. Memory usage increase after applying KB5001337 Patch

    in Windows 10 Installation and Upgrade
    Memory usage increase after applying KB5001337 Patch: Hi,We have a .Net Application which suddenly started taking about 10G to 14GB of Memory when run on Windows 10 1909 machine with KB5001337 Patch applied to it.. On uninstalling this package, we get the Memory usage by this application back to nominal amount 100...
  6. Security Patch

    in AntiVirus, Firewalls and System Security
    Security Patch: Hi All, How to download the KB4049411 and KB4033631 in Microsoft catalog? If we select "Check for Update" , these two patches are showing , but in Microsoft catalog mentioned KB's are not shown....
  7. after uninstalling a security patch, another patch install automatically

    in Windows 10 Installation and Upgrade
    after uninstalling a security patch, another patch install automatically: i'm using windows 10 with 1903 version. I installed one security patch KB4551762 to fix SMB issue, but due to some reason, I have to uninstall it the other day. after I uninstall it and reboot the system, then login the system as usual, then find there is any update installed...
  8. After MS security patch D drive got write protected.

    in Windows 10 Support
    After MS security patch D drive got write protected.: After MS security patch D drive got write protected. Hello, I just update all my systems with latest MS security patch KB4537480. after updating my systems with this patch I am getting an error for my D or other drive, All these drives are automatically got write protected ad...
  9. After MS security patch D drive got write protected.

    in Windows 10 Updates and Activation
    After MS security patch D drive got write protected.: After MS security patch D drive got write protected. Hello, I just update all my systems with latest MS security patch KB4537480. after updating my systems with this patch I am getting an error for my D or other drive, All these drives are automatically got write protected ad...
  10. Secure boot issues

    in Windows 10 Installation and Upgrade
    Secure boot issues: Hi, I am using an acer travelmate laptop and I'm attempting to boot from an official (I think) windows 10 DVD, I downloaded it using the media creation tool (as a dual x64-x86 iso) and created a bootable iso from the x64 portion (with imgburn) the disk definitely works as I...

Users found this page by searching for:

  1. do Windows server patches get applied before or after a restart