Windows 10: Windows Boothole vulnerability - how to verify if it is fixed

Discus and support Windows Boothole vulnerability - how to verify if it is fixed in Windows 10 Support to solve the problem; Boothole vulnerability BootHole vulnerability in Secure Boot affecting Linux and Windows Windows has recently released a patch for the boothole... Discussion in 'Windows 10 Support' started by z080236, Feb 19, 2021.

  1. z080236 Win User

    Windows Boothole vulnerability - how to verify if it is fixed


    Boothole vulnerability

    BootHole vulnerability in Secure Boot affecting Linux and Windows


    Windows has recently released a patch for the boothole vulnerability

    https://support.microsoft.com/en-us/...7-d0c32ead81e2


    Based on the https://msrc.microsoft.com/update-gu.../CVE-2020-0689

    For Windows server 2016
    I installed the update based on this:
    1. Servicing Stack Update KB4576750
    2. Standalone Secure Boot Update Listed in this CVE KB4535680
    3. Jan 2021 Security Update KB4598243


    Based on https://msrc.microsoft.com/update-gu...lity/ADV200011
    I just run this command to verify?

    [System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Microsoft Corporation UEFI CA 2011'

    :)
     
    z080236, Feb 19, 2021
    #1
  2. Brink Win User

    BootHole vulnerability in Secure Boot affecting Linux and Windows

    Read more: https://eclypsium.com/2020/07/29/the...e-in-the-boot/
     
    Brink, Feb 19, 2021
    #2
  3. Yukikaze Win User
    WPA2 Vulnerability Found

    A small update with regards to the Microsoft fix. The fix itself is sufficient to solve the issue on Windows, even if your WiFi device has no driver update, with one caveat:

    Does this security update fully address these vulnerabilities on Microsoft Platforms, or do I need to perform any additional steps to be fully protected?
    The provided security updates address the reported vulnerabilities; however, when affected Windows based systems enter a connected standby mode in low power situations, the vulnerable functionality may be offloaded to installed Wi-Fi hardware. To fully address potential vulnerabilities, you are also encouraged to contact your Wi-Fi hardware vendor to obtain updated device drivers. For a listing of affected vendors with links to their documentation, review the ICASI Multi-Vendor Vulnerability Disclosure statement here: http://www.icasi.org/wi-fi-protected-access-wpa-vulnerabilities

    Source: Security Update Guide - Microsoft Security Response Center
     
    Yukikaze, Feb 19, 2021
    #3
  4. Windows Boothole vulnerability - how to verify if it is fixed

    vulnerability fix

    What "below vulnerability" would that be?

    Hint: review your posting after being submitted to verify that all of the information that you wish to relate when asking a question is present and relevant to your query at hand.

    We'll be waiting for your next reply.

    -Richard
     
    RichardEiler, Feb 19, 2021
    #4
Thema:

Windows Boothole vulnerability - how to verify if it is fixed

Loading...
  1. Windows Boothole vulnerability - how to verify if it is fixed - Similar Threads - Boothole vulnerability verify

  2. Failed to register and start service for the vulnerable driver - How to fix?

    in Windows 10 Gaming
    Failed to register and start service for the vulnerable driver - How to fix?: I'm getting an error in a pkg I'm trying to run that is coming up with:[-] Failed to register and start service for the vulnerable driver [-] Driver Unload Failed!!Any idea why this would happen?...
  3. Failed to register and start service for the vulnerable driver - How to fix?

    in Windows 10 Software and Apps
    Failed to register and start service for the vulnerable driver - How to fix?: I'm getting an error in a pkg I'm trying to run that is coming up with:[-] Failed to register and start service for the vulnerable driver [-] Driver Unload Failed!!Any idea why this would happen?...
  4. how can i fix verifier violation on windows 11

    in Windows 10 Gaming
    how can i fix verifier violation on windows 11: ive tried everything the Internet has told me to fix this issue but nothing works and i can't boot my PC into safe mode at all to reset and troubleshoot...
  5. how can i fix verifier violation on windows 11

    in Windows 10 Software and Apps
    how can i fix verifier violation on windows 11: ive tried everything the Internet has told me to fix this issue but nothing works and i can't boot my PC into safe mode at all to reset and troubleshoot...
  6. KB5012170 Secure Boothole is already installed.

    in Windows 10 Installation and Upgrade
    KB5012170 Secure Boothole is already installed.: A few months back, KB5012170 was released to fix a vulnerability in Windows Security Feature Bypass in Secure Boot BootHole. We've installed this fix KB via SCCM and Powershell and confirmed that it is actually installed. However, Tenable is still detecting that the device is...
  7. KB5012170 Secure Boothole is already installed.

    in Windows 10 Software and Apps
    KB5012170 Secure Boothole is already installed.: A few months back, KB5012170 was released to fix a vulnerability in Windows Security Feature Bypass in Secure Boot BootHole. We've installed this fix KB via SCCM and Powershell and confirmed that it is actually installed. However, Tenable is still detecting that the device is...
  8. How to verify fix for Windows 10 KB5001330 performance issues

    in Windows 10 News
    How to verify fix for Windows 10 KB5001330 performance issues: Over the past few weeks, there have been reports of Windows 10 encountering moderate to severe performance issues after applying KB5001330. Affected users have reported various issues, which includes system lag, FPS drop and stuttering when playing certain games. Windows 10...
  9. BootHole vulnerability in Secure Boot affecting Linux and Windows

    in Windows 10 News
    BootHole vulnerability in Secure Boot affecting Linux and Windows: [ATTACH] “BootHole” vulnerability in the GRUB2 bootloader opens up Windows and Linux devices using Secure Boot to attack. All operating systems using GRUB2 with Secure Boot must release new installers and bootloaders. Join Eclypsium for a webinar...
  10. Unpatched Windows Vulnerability Gets a 3rd Party Fix

    in Windows 10 News
    Unpatched Windows Vulnerability Gets a 3rd Party Fix: A third-party security group called 0patch and created by experts at ACROS Security released a third-party patch for the Windows gdi32.dll memory disclosure bug in an attempt to address the vulnerability until Microsoft ships a patch. This is projected to happen on March 14...