Reminder: Changes to Windows Boot Manager revocations for Secure Boot effective April 9, 2024

  • Home |
  • Reminder: Changes to Windows Boot Manager revocations for Secure Boot effective April 9, 2024

MC708249 · Windows, Custom Software Development

From Microsoft Corporation
Technical Bulletin MC708249 · Published Jan 18, 2024

Message Summary

Windows updates released July 11, 2023 and later include security measures which protect against a Secure Boot bypass vulnerability disclosed in CVE-2023-24932Secure Boot is a Windows security feature designed to protect devices from bootkit malware.

Windows security updates include options to manually enable protections against Secure Boot bypass beginning July 11, 2023. Enforcement and deployment phases for these protections are coming with updates being released on April 9, 2024, and throughout 2024. For detailed information, see KB5025885: How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932.

When will this happen:

April 9, 2024 or later – Third Deployment Phase

  • Windows updates released on and after this date will provide new mitigations to block additional vulnerable boot managers.

October 8, 2024 or later – Mandatory Enforcement Phase

  • Windows updates released on and after this date which are installed to affected systems will enforce the Code Integrity Boot policy and Secure Boot disallow list revocations related to this hardening. There will be no option to disable this enforcement after this update.

The Mandatory Enforcement Phase described above is the final phase of these security hardening measures.

What you need to do to prepare:

Administrators should determine whether it’s important to enable protections now or wait for a future update from Microsoft. It’s also important to understand the options available for configuring these security requirements in your environment. See the resources available in the Additional information section below.

Additional information:

Recent Comments

No comments to show.

Recent Posts

Microsoft 365 Curtain Reveal Tech Bulletin Header
New Outlook for Windows: Auto-reading emails with Microsoft Windows Narrator
October 14, 2024
Microsoft 365 Curtain Reveal Tech Bulletin Header
(Updated) Microsoft Purview: Minor encrypted message portal design updates, URL to remain the same
October 14, 2024
Microsoft Exchange Curtain Reveal Tech Bulletin Header
(Updated) Microsoft Defender for Office 365: Tenant Allow/Block List will support IPv6 allow and block entries
October 14, 2024