{"id":34726,"date":"2024-08-07T00:03:48","date_gmt":"2024-08-06T22:03:48","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=34726"},"modified":"2024-08-07T00:16:40","modified_gmt":"2024-08-06T22:16:40","slug":"attention-microsofts-uefi-certificate-expires-on-oct-19-2026-secure-boot-affected","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2024\/08\/07\/attention-microsofts-uefi-certificate-expires-on-oct-19-2026-secure-boot-affected\/","title":{"rendered":"Attention: Microsoft's UEFI certificate expires on Oct. 19, 2026 &#8211; Secure Boot affected"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Windows\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Windows-klein.jpg\" alt=\"Windows\" width=\"200\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2024\/08\/07\/achtung-microsofts-uefi-zertifikat-luft-am-19-okt-2026-aus-secure-boot-betroffen\/\">German<\/a>]I'm posting a topic here in the blog that still has \"a few days to go\" but could have very unpleasant consequences. In the fall of 2026, a certificate in Windows will expire, which ensures that Secure Boot can be executed in the UEFI. At that time, the certificate was valid for 15 years, but all machines that are not updated will no longer be able to start in Secure Boot mode by the deadline.<\/p>\n<p><!--more--><\/p>\n<h2>Windows and the Secure Boot CA<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg09.met.vgwort.de\/na\/2c54768fd8fa4e22a897481ae4cc3e38\" alt=\"\" width=\"1\" height=\"1\" \/>I came across the following <a href=\"https:\/\/x.com\/etguenni\/status\/1819397211945308218\" target=\"_blank\" rel=\"noopener\">tweet<\/a> by Gunnar Haslinger a few days ago and am posting it here on the blog today for your information.<\/p>\n<p><a href=\"https:\/\/x.com\/etguenni\/status\/1819397211945308218\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"Microsoft UEFI CA\" src=\"https:\/\/i.postimg.cc\/GhSv8P9s\/image.png\" alt=\"Microsoft UEFI CA\" \/><\/a><\/p>\n<p>The issue at hand is described in a few words. Microsoft uses a UEFI certificate that is stored in a database. The Secure Boot propagated by Microsoft in Windows accesses this certificate to check its integrity. Secure Boot therefore depends on the validity of this certificate. If the certificate in the <em>bootmgfw.efi<\/em> file on the UEFI partition is invalid, the machine can no longer start in Secure Boot.<\/p>\n<h3>The Windows Production PCA 2011<\/h3>\n<p>However, the certificate used so far was issued a long time ago, specifically in 2011, and will expire on Monday, October 19, 2026, after 15 years of validity. Machines that use Secure Boot and have not been updated by this date will no longer be able to start. This is likely to affect Windows systems in particular, which do not receive updates via the internet.<\/p>\n<h3>The Black Lotus problem<\/h3>\n<p>With the May 2023 security updates, Microsoft has attempted to close the vulnerability in Secure Boot that is being exploited by the hacker group BlackLotus and its UEFI bootkit. The vulnerability <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2023-24932\" target=\"_blank\" rel=\"noopener\">CVE-2023-24932<\/a> relates to a vulnerability in the Secure Boot used in Windows operating systems, which allows untrusted software to be executed during the boot process.<\/p>\n<p>I wrote about this topic in the blog post <a href=\"https:\/\/borncity.com\/win\/2023\/03\/01\/blacklotus-uefi-bootkit-bypasses-secure-boot-in-windows-11\/\">BlackLotus UEFI bootkit bypasses Secure Boot in Windows 11<\/a>. And in the German article <a href=\"https:\/\/www.borncity.com\/blog\/2023\/06\/25\/windows-und-das-secure-boot-desaster-microsoft-braucht-fast-ein-jahr-zum-fixen\/\">Windows und das (BlackLotus) Secure Boot-Desaster: Wie ist bei euch der Status?<\/a> I discussed the problem of administrators having to intervene manually to secure the Secure Boot.<\/p>\n<h2>New Windows UEFI CA 2023<\/h2>\n<p>To solve the problem with the expiring certificate, Microsoft has provided the update KB5025885 for protection (see <a href=\"https:\/\/borncity.com\/win\/2023\/05\/13\/kb5025885-secure-boot-hardening-against-vulnerability-cve-2023-24932-black-lotus\/\">KB5025885: Secure boot hardening against vulnerability CVE-2023-24932 (Black Lotus)<\/a> from May 2023). There is also a <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d\" target=\"_blank\" rel=\"noopener\">support article on update KB5025885<\/a>, which contains the advice to install the Windows security update of July 9, 2024 or a later cumulative security update under Windows in order to provide the required safeguards against Black Lotus.<\/p>\n<p>This blog post also contains a note that a new certificate (Windows UEFI CA 2023) will be provided with the update to replace the old Windows Production PCA 2011. Administrators in enterprise environments will find corresponding instructions in the support article for <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d\" target=\"_blank\" rel=\"noopener\">KB5025885<\/a> as to which additional steps need to be carried out. Anyone who provides their Windows systems with protection against Black Lotus and the Secure Boot vulnerability <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-24932\">CVE-2023-24932<\/a> is also prepared for the scenario of an expiring UEFI certificate outlined above.<\/p>\n<p>In 2024, Microsoft then carry out various hardening measures, which I outlined in the blog post <a href=\"https:\/\/borncity.com\/win\/2024\/03\/15\/update-on-windows-handening-in-2024-2025-march-2024\/\">Update on Windows hardening in 2024\/2025 \u2013 March 2024<\/a>.<\/p>\n<p><strong>Similar articles:<br \/>\n<\/strong><a href=\"https:\/\/borncity.com\/win\/2023\/03\/01\/blacklotus-uefi-bootkit-bypasses-secure-boot-in-windows-11\/\">BlackLotus UEFI bootkit bypasses Secure Boot in Windows 11<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2023\/05\/13\/kb5025885-secure-boot-hardening-against-vulnerability-cve-2023-24932-black-lotus\/\">KB5025885: Secure boot hardening against vulnerability CVE-2023-24932 (Black Lotus)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/03\/15\/update-on-windows-handening-in-2024-2025-march-2024\/\">Update on Windows hardening in 2024\/2025 \u2013 March 2024<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]I'm posting a topic here in the blog that still has \"a few days to go\" but could have very unpleasant consequences. In the fall of 2026, a certificate in Windows will expire, which ensures that Secure Boot can be &hellip; <a href=\"https:\/\/borncity.com\/win\/2024\/08\/07\/attention-microsofts-uefi-certificate-expires-on-oct-19-2026-secure-boot-affected\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,2],"tags":[69,194],"class_list":["post-34726","post","type-post","status-publish","format-standard","hentry","category-security","category-windows","tag-security","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/34726","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=34726"}],"version-history":[{"count":3,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/34726\/revisions"}],"predecessor-version":[{"id":34730,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/34726\/revisions\/34730"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=34726"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=34726"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=34726"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}