web analytics
Home » Technology » Microsoft » Windows » Windows 11 22H2 Gets Secure Boot Update

Windows 11 22H2 Gets Secure Boot Update

Windows 11 version 22H2

Microsoft has started the distribution of a Secure Boot DBX update for Windows 11, version 22H2. This update was originally released in August but was then held back for the new Windows 11 due to issues with other Windows versions.

Now the Secure Boot DBX update KB5012170 is also available for the latest Windows 11 version. There is no corresponding change listed in the knowledge base.

The security update for DBX, a database that lists signatures that are not trustworthy (Secure Boot Forbidden Signature Database), was released on patch day in August. The update was released as a separate security update for all Windows versions from Windows 8.1 to Windows 11 and for Azure Stack.

A variety of problems surfaced

The first error messages followed the next day, users could only apply the update if they also performed an UEFI update. After that, more and more problems surfaced.

Microsoft was able to weed out the bugs and restart the updates, but until now had not distributed a separate update for the latest Windows 11 version. However, this is not a trivial problem that Microsoft is addressing with KB5012170, so starting the distribution for Windows 11 22H2 is now also an important step. We have already reported several times about the background to the update: Microsoft has excluded various third-party boot loaders from safe starting. These boot loaders were initially signed by Microsoft and thus approved as trustworthy for the “Secure Boot” process (secure start).

However, these bootloaders are suspected of allowing third-party systems to be taken over and overriding Windows security measures. Bypassing Secure Boot checks allows threat actors to launch attacks, modify the operating system, disable security controls, and install more backdoors.