{"id":19399,"date":"2021-03-27T07:21:45","date_gmt":"2021-03-27T06:21:45","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=19399"},"modified":"2022-11-04T11:43:38","modified_gmt":"2022-11-04T10:43:38","slug":"windows-10-neues-ssu-kb5001205-fixt-security-boot-schwachstelle","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2021\/03\/27\/windows-10-neues-ssu-kb5001205-fixt-security-boot-schwachstelle\/","title":{"rendered":"Windows 10: New SSU KB5001205 fixes Secure Boot issues"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/win102.jpg\" width=\"58\" height=\"58\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2021\/03\/27\/windows-10-neues-ssu-kb5001205-fixt-security-boot-schwachstelle\/\" target=\"_blank\" rel=\"noopener\">English<\/a>]Microsoft has released a new Servicing Stack Update (SSU) for Windows 10. The SSU KB5001205 is supposed to fix a vulnerability in the fixt Security Boot. This vulnerability was torn open by a previous update for the Security Boot.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg08.met.vgwort.de\/na\/b41eac078ba146199f3a007662542ee7\" alt=\"\" width=\"1\" height=\"1\" \/>Yesterday I had reported in the blog post <a href=\"https:\/\/borncity.com\/win\/2021\/03\/26\/windows-10-1809-1909-preview-updates-25-3-2021\/\">Windows 10 1809\/1909: Preview Updates (March 25, 2021)<\/a>\u00a0 about preview updates for Windows 10. The preview update is supposed to fix a number of issues and remove the old Edge browser from the Windows 10 version 1909 in question.<\/p>\n<h2>New SSU KB5001205 for Windows 10 Version 1909<\/h2>\n<p>Service Stack Update (SSU) <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/kb5001205-servicing-stack-update-for-windows-10-version-1909-march-25-2021-42e15cd8-df54-4f0f-ac9f-266dd5de278e\" target=\"_blank\" rel=\"noopener\">KB5001205<\/a> has also been mentioned for Windows 10 version 1909, and Microsoft strongly recommends installing it. I now took a closer look at the description of this SSU , which was released for the Intel and ARM versions of Windows 10 version 1909 and Windows Server version 1909 (Server Core installation). The support article states.<\/p>\n<blockquote><p>This update makes quality improvements to the servicing stack, which is the component that installs Windows updates. Servicing stack updates (SSU) makes sure that you have a robust and reliable servicing stack so that your devices can receive and install Microsoft updates.<\/p><\/blockquote>\n<p>This is nothing new, as improving the quality and stability of the servicing stack and Windows Update is always the goal of the now probably monthly SSUs. But there is another addition that targets a security boot vulnerability.<\/p>\n<blockquote><p>This update also addresses an issue that might prevent the CVE-2020-0689 update from installing. The error message in the CBS.log file is <b>TRUST_E_NOSIGNATURE<\/b>. To learn more about this security vulnerability, see <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2020-0689\" target=\"_blank\" rel=\"noopener\">CVE-2020-0689 | Microsoft Secure Boot Security Feature Bypass Vulnerability<\/a>.<\/p><\/blockquote>\n<p>There, the reader learns that the SSU also fixes a problem that prevents the update for CVE-2020-0689 from being installed. Microsoft doesn't give any further details there.<\/p>\n<blockquote><p>The TRUST_E_NOSIGNATURE error (error code 0x800b0100) probably signals that no valid signature was found in the package. Since the SSU was only released for Windows 10 V1909, it does not seem to have been a problem with the update, but a problem with the servicing stack in Windows Update.<\/p><\/blockquote>\n<p>This SSU update is offered via Windows Update on appropriate systems, but can also be downloaded via <a href=\"https:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=5001205\" target=\"_blank\" rel=\"noopener\">Microsoft Update Catalog<\/a> as a package and then installed manually. In addition, Microsoft offers this update in WSUS for distribution to affected machines, they probably attach a high importance to the problem.<\/p>\n<h3>The background of the vulnerability<\/h3>\n<p>In January 2021, there was security update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4535680\/security-update-for-secure-boot-dbx\" target=\"_blank\" rel=\"noopener\">KB4535680<\/a> (Security update for Secure Boot DBX: January 12, 2021), which I covered in the blog post <a href=\"https:\/\/borncity.com\/win\/2021\/01\/14\/windows-sicherheitsupdate-kb4535680-fr-secure-boot-dbx\/\">Windows Security Update KB4535680 for Secure Boot (DBX)<\/a>. Windows devices with UEFI (Unified Extensible Firmware Interface)-based firmware had a vulnerability that allows bypassing security features in Secure Boot (see <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2020-0689\">CVE-2020-0689 | Microsoft Secure Boot Security Feature Bypass Vulnerability<\/a>). The Secure Boot Forbidden Signature Database (DBX) could not prevent UEFI modules from loading. An attacker who successfully exploited this vulnerability could bypass Secure Boot and load untrusted software. Security update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4535680\/security-update-for-secure-boot-dbx\" target=\"_blank\" rel=\"noopener\">KB4535680<\/a> (Security update for Secure Boot DBX: January 12, 2021) made improvements to Secure Boot DBX for supported Windows versions in this regard by adding new modules to DBX. The security update was rolled out for Windows 8.1\/Server 2012\/R2 through Windows 10 version 1909 and its server counterparts.<\/p>\n<h3>Issues with Bitlocker systems<\/h3>\n<p>Update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4535680\/security-update-for-secure-boot-dbx\" target=\"_blank\" rel=\"noopener\">KB4535680<\/a> has also another issue beside the error message TRUST_E_NOSIGNATURE left in the CBS.log. Searching this blog, I found the article <a href=\"https:\/\/borncity.com\/win\/2021\/02\/16\/windows-10-lst-kb4535680-ein-bitlocker-recovery-aus\/\">Windows 10: KB4535680 may trigger a Bitlocker Recovery<\/a>. There I had reported that this update triggered a Bitlocker recovery on various Windows 10 devices after installation. Especially HP devices seem to be affected &#8211; but also Surface Laptop 1\/2 was mentioned. Was anyone affected by this issue and is it fixed by the SSU? (via)<\/p>\n<p><strong>Similar articles<\/strong><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/01\/14\/windows-sicherheitsupdate-kb4535680-fr-secure-boot-dbx\/\">Windows Security Update KB4535680 for Secure Boot (DBX)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2021\/02\/16\/windows-10-lst-kb4535680-ein-bitlocker-recovery-aus\/\">Windows 10: KB4535680 may trigger a Bitlocker Recovery<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[English]Microsoft has released a new Servicing Stack Update (SSU) for Windows 10. The SSU KB5001205 is supposed to fix a vulnerability in the fixt Security Boot. This vulnerability was torn open by a previous update for the Security Boot.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,22,2],"tags":[69,195,76],"class_list":["post-19399","post","type-post","status-publish","format-standard","hentry","category-security","category-update","category-windows","tag-security","tag-update","tag-windows-10"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/19399","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=19399"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/19399\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=19399"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=19399"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=19399"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}