{"id":28768,"date":"2023-02-16T07:48:05","date_gmt":"2023-02-16T06:48:05","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=28768"},"modified":"2024-10-05T19:05:33","modified_gmt":"2024-10-05T17:05:33","slug":"windows-server-2022-february-2023-patchday-and-the-esxi-vm-secure-boot-issue","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2023\/02\/16\/windows-server-2022-february-2023-patchday-and-the-esxi-vm-secure-boot-issue\/","title":{"rendered":"Windows Server 2022: February 2023 Patchday and the ESXi VM Secure Boot Issue"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" width=\"200\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2023\/02\/16\/windows-server-2022-februar-2023-patchday-und-des-esxi-vm-secure-boot-problem\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]The security update KB5022842 for Windows Server, released on February 14, 2023,\u00a0 triggers collateral damage. Virtual machines can subsequently no longer start after a reboot and either can no longer find their system drives or trigger a Secure Boot error. Disabling Secure Boot helps &#8211; Microsoft and VMware have since confirmed this error.<\/p>\n<p><!--more--><\/p>\n<h2>Boot issues with VMs<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg05.met.vgwort.de\/na\/9ad31595b8344a87b139964a78aa94ce\" alt=\"\" width=\"1\" height=\"1\" \/>I had presented the security update <a href=\"https:\/\/support.microsoft.com\/help\/5022842\" target=\"_blank\" rel=\"noopener\">KB5022842<\/a> released for Windows Server 2022 in the blog post <a href=\"https:\/\/borncity.com\/win\/2023\/02\/15\/patchday-windows-11-server-2022-updates-february-14-2023\/\">Patchday: Windows 11\/Server 2022 Updates (February 14, 2023)<\/a>. Shortly after the German edition of this post was published, users already came forward <a href=\"https:\/\/www.borncity.com\/blog\/2023\/02\/15\/patchday-windows-11-server-2022-updates-14-februar-2023\/#comment-142436\" target=\"_blank\" rel=\"noopener\">reporting issues<\/a> (I've translated the comments).<\/p>\n<blockquote><p>User #1: My template Win 2022 VM does not boot up after the update once you turn it off.<\/p>\n<p>User #2: Windows Server 2022 with Secure Boot \/ VBS enabled in the VMware are having problems after the Feb. update and will not boot.<\/p>\n<p>First comes: Windows Boot Manager&#8230; Security Violation<br \/>\nThen Windows Boot Manager&#8230; unsuccessful<\/p>\n<p>Can anyone confirm this?<\/p>\n<p>User #3: Same problem, ESXi 7.0.3<br \/>\nAfter update the server is running, after further boot<br \/>\ncomes \"Security Violation<br \/>\nDisabling the Secure Boot solves the problem<\/p>\n<p>User #4: Same problem with our Win 2022 server VMs. By disabling VBS and Secure Boot the VM boots up again. (ESXi 7.0.3 environment)<\/p><\/blockquote>\n<p>German blog reader Dennis C. also contacted me by e-mail and reported the error at the VMs:<\/p>\n<blockquote><p>Dear Mr. Born!<\/p>\n<p>First of all, thank you for your website, it has helped me a few times.<\/p>\n<p>I don't know if we are a unique case, but since today we have a problem that I would like to share with you. Maybe you can verify it and publish it:<\/p>\n<p>I have the following problem with a customer (Server 2022): If there is a VM in version 19, the server member is a domain and receives the February update (KB5022842), the server does not survive the next reboot.<\/p>\n<p>Using the console, you can still see the following before going into the boot options:<\/p><\/blockquote>\n<p><img decoding=\"async\" title=\"VMware Seciroty Violation message\" src=\"https:\/\/i.imgur.com\/pPzT5BK.png\" alt=\"VMware Seciroty Violation message\" \/><\/p>\n<blockquote><p>If I now disable the security boot in the VM options, the server starts again as usual:<\/p><\/blockquote>\n<p><img decoding=\"async\" title=\"ESXi-Settings\" src=\"https:\/\/i.imgur.com\/nS7IoD8.png\" alt=\"ESXi-Settings\" \/><\/p>\n<blockquote><p>Interestingly, the 3 requirements had to coincide in my case. A server in VM version 16 was not affected, there was no secure boot option.<\/p><\/blockquote>\n<p>I then pointed Dennis to the discussion on the blog. Within my English blog post <a href=\"https:\/\/borncity.com\/win\/2023\/02\/15\/patchday-windows-11-server-2022-updates-february-14-2023\/\">Patchday: Windows 11\/Server 2022 Updates (February 14, 2023)<\/a> I've added the following warning:<\/p>\n<blockquote><p><strong>Addendum:<\/strong>\u00a0I got\u00a0<a href=\"https:\/\/www.borncity.com\/blog\/2023\/02\/15\/patchday-windows-11-server-2022-updates-14-februar-2023\/#comment-142437\">several reports<\/a> from German blog readers, saying, that their virtual machines can't boot either due to a \"security violation\" or due to a missing boot manager. Deactivating \"Secure boot\" should solve the issue.<\/p><\/blockquote>\n<p>The topic is also discussed on patchlist.org:<\/p>\n<blockquote><p>So far this is isolated to a single VM on VMware ESXI, but we have a server 2022, new install from about 2 weeks ago, installed updated Ok, rebooted OK.<\/p>\n<p>Just rebooted again and it's got a \"security violation.\"<\/p>\n<p>Turning off VBS and secure boot seems to have fixed it for now.<\/p><\/blockquote>\n<p>There came the hint that on reddit.com in the <a href=\"https:\/\/www.reddit.com\/r\/sysadmin\/comments\/1128v87\/patch_tuesday_megathread_20230214\/\" target=\"_blank\" rel=\"noopener\">patchday superthread<\/a> as well as <a href=\"https:\/\/www.reddit.com\/r\/sysadmin\/comments\/112xt69\/securityviolation_on_boot_ws2022_with_esxi_exsi\/\" target=\"_blank\" rel=\"noopener\">here<\/a> the error was also reported. Martin noted on Facebook in an admin group to my post still:<\/p>\n<blockquote><p>It is certainly also important that the first restart works. So the server runs after the updates first. Only after the next regular restart, the problem then occurs. Only times as info for all those who perhaps feel safe that it is not with you.<\/p><\/blockquote>\n<p>These are probably all cases where VMware ESCi is used for virtualization. Uninstalling KB5022842 does not fix the problem <a href=\"https:\/\/www.borncity.com\/blog\/2023\/02\/15\/patchday-windows-11-server-2022-updates-14-februar-2023\/#comment-142478\" target=\"_blank\" rel=\"noopener\">according to Simon<\/a> because the EFI files seem to remain in the new version.<\/p>\n<p>In <a href=\"https:\/\/www.borncity.com\/blog\/2023\/02\/15\/patchday-windows-11-server-2022-updates-14-februar-2023\/#comment-142443\" target=\"_blank\" rel=\"noopener\">this comment<\/a>, one refers to problems with Windows Server 2019 and Hyper-V, which is confirmed by a second user, but doesn't really correspond with above descriptions. And <a href=\"https:\/\/www.borncity.com\/blog\/2023\/02\/15\/patchday-windows-11-server-2022-updates-14-februar-2023\/#comment-142509\">this comment<\/a> reports Citrix PVS vdisks\/machines not starting after the update.<\/p>\n<h2>VMware &amp; Microsoft confirms the bug<\/h2>\n<p>Andi has already posted<a href=\"https:\/\/www.borncity.com\/blog\/2023\/02\/15\/patchday-windows-11-server-2022-updates-14-februar-2023\/#comment-142511\" target=\"_blank\" rel=\"noopener\"> this comment<\/a> on the German blog (thanks for that) and reported that a colleague has opened a support case with Microsoft:<\/p>\n<blockquote><p>A colleague has opened a call at MS.<br \/>\nMS is aware of the error, it is caused by ESXI.<br \/>\nESXI 8.0 does not have the problem.<br \/>\nEither a patch will come from MS or from VMWare.<\/p><\/blockquote>\n<p>In the meantime VMware has published the support post <a href=\"https:\/\/kb.vmware.com\/s\/article\/90947\" target=\"_blank\" rel=\"noopener\">Virtual Machine with Windows Server 2022 KB5022842 (OS Build 20348.1547) configured with secure boot enabled not booting up (90947)<\/a> about this &#8211; thanks to <a href=\"https:\/\/www.borncity.com\/blog\/2023\/02\/15\/patchday-windows-11-server-2022-updates-14-februar-2023\/#comment-142541\" target=\"_blank\" rel=\"noopener\">Michael<\/a> and other blog readers on Facebook for pointing this out. This <a href=\"https:\/\/web.archive.org\/web\/20240304140920\/https:\/\/www.reddit.com\/r\/vmware\/comments\/112xea3\/microsoft_februari_2023_update_breaks_server_2022\/\" target=\"_blank\" rel=\"noopener\">reddit.com post<\/a> summarizes the error again and provides the reference to VMware's support post. The VMware support post describes the bug and states:<\/p>\n<blockquote><p>Currently there is no resolution for virtual machines running on vSphere ESXi 6.7 U2\/U3 and vSphere ESXi 7.0.x. However the issue doesn't exist with virtual machines running on vSphere ESXi 8.0.x. vSphere ESXi 6.7 is End of general Support.<\/p>\n<p>Uninstalling the <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2023-Feb\" target=\"_blank\" rel=\"noopener\">KB5022842<\/a> patch will not resolve the issue. If the Virtual machine has already been updated, then the only available options are:<\/p>\n<ol>\n<li>Upgrade the ESXi Host where the virtual machine in question is running to vSphere ESXi 8.0<\/li>\n<li>Disable \"Secure Boot\" on the VMs.<\/li>\n<\/ol>\n<\/blockquote>\n<p>The support article then mentions upgrading to vSphere ESXi 8.0 and disabling Secure Boot in the VMs. VMware warns against the installation of the update KB5022842 on a virtual machine with Windows 2022 Server until the problem is solved. Meanwhile, Microsoft has posted the article <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/release-health\/status-windows-server-2022#3017msgdesc\" target=\"_blank\" rel=\"noopener\">Windows Server 2022 might not start up<\/a> in the Windows Server 2022 Health Status section under Known Issues.<\/p>\n<blockquote><p>After installing <a href=\"https:\/\/support.microsoft.com\/help\/5022842\" target=\"_blank\" rel=\"noopener\">KB5022842<\/a> on guest virtual machines (VMs) running Windows Server 2022 on some versions of VMware ESXi, Windows Server 2022 might not start up. Only Windows Server 2022 VMs with Secure Boot enabled are affected by this issue. Affected versions of VMware ESXi are versions vSphere ESXi 7.0.x and below.<\/p><\/blockquote>\n<p>Please refer to the VMware support article above. Microsoft and VMware are investigating this issue and will provide more information as it becomes available.<\/p>\n<p><strong>Addendum:<\/strong> The bug has been fixed for some ESXi versions, see <a href=\"https:\/\/borncity.com\/win\/2023\/02\/22\/windows-server-2022-vmware-esxi-7-0-u3k-patch-for-secure-boot-issue-update-kb5022842-feb-2023\/\">Windows Server 2022: VMware ESXi 7.0 U3k Patch for Secure Boot Issue (Update KB5022842, Feb. 2023)<\/a>.<\/p>\n<p><strong>Similar articles:<\/strong><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/02\/15\/microsoft-security-update-summary-february-14-2023\/\" target=\"_blank\" rel=\"noopener\">Microsoft Security Update Summary (February 14, 2023)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/02\/15\/patchday-windows-10-updates-february-14-2023\/\" target=\"_blank\" rel=\"noopener\">Patchday: Windows 10 Updates (February 14, 2023)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/02\/15\/patchday-windows-11-server-2022-updates-february-14-2023\/\">Patchday: Windows 11\/Server 2022 Updates (February 14, 2023)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/02\/15\/windows-7-server-2008-r2-server-2012-r2-updates-february-14-2023\/\">Windows 7\/Server 2008 R2; Server 2012 R2: Updates (February 14, 2023)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/?p=28764\">Patchday: Microsoft Office Updates (February 14, 2023)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/02\/15\/exchange-server-security-updates-february-14-2023\/\">Exchange Server Security Updates (February 14, 2023<\/a>)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]The security update KB5022842 for Windows Server, released on February 14, 2023,\u00a0 triggers collateral damage. Virtual machines can subsequently no longer start after a reboot and either can no longer find their system drives or trigger a Secure Boot error. &hellip; <a href=\"https:\/\/borncity.com\/win\/2023\/02\/16\/windows-server-2022-february-2023-patchday-and-the-esxi-vm-secure-boot-issue\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1319],"tags":[],"class_list":["post-28768","post","type-post","status-publish","format-standard","hentry","category-general"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/28768","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=28768"}],"version-history":[{"count":1,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/28768\/revisions"}],"predecessor-version":[{"id":35737,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/28768\/revisions\/35737"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=28768"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=28768"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=28768"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}