Microsoft is updating Secure boot 22-24 july (posted June 9, 2026)

Condobloke

Well-Known Member
Joined
Apr 30, 2017
Messages
13,385
Reaction score
11,319
Credits
96,255


1st reply there states :

I'm not sure if you know but Microsoft is updating secure bootloader end of july.
The security update applies only to the following Windows versions, none of which are current versions:

  • Windows Server 2012
  • Windows 8.1 and Windows Server 2012 R2
  • Windows 10, version 1507
  • Windows 10, version 1607 and Windows Server 2016
  • Windows 10, version 1809 and Windows Server 2019
  • Windows 10, version 20H2
  • Windows 10, version 21H1
  • Windows 10, version 21H2
  • Windows 10, version 22H2
  • Windows Server 2022
  • Windows 11, version 21H2
  • Windows 11, version 22H2
  • Azure Stack HCI, version 1809
  • Azure Stack Data Box, version 1809 (ASDB)
Source: KB5012170: Security update for Secure Boot DBX

I'm not sure if this is normal proceder or if they are cracking down on what they think is "unsecure" OS.
Read the link and you will understand the purpose and scope of the update. Several CVE's have been uncovered and the update patches the vulnerabilities.

Anyway, how can i prepare myself from this update? i have been reading on website about this but i'm not that technical to understand it.
You don't need to do anything if you are running a reasonably current version of Windows. Check Settings > System > About > Windows Information to see what Windows version you are running. If the version you are running (probably 25H2 if you update regularly) is not listed, the update does not apply to you.
 
Updates to 8.1 and 10. Both are EOL and have been.

There must be enough stragglers for MSFT to feel that they need to ship a patch to people using those versions of Windows.
 
Turns out MS has been idling on restricting vulnerable Linux shims for years, and they are signed by the old 2011 certificate. So, anyone using Linux while relying on secure-boot enabled indeed must care a lot to get this updated:

 
As I have secure boot disabled on my Tower's Motherboard and not using windoze...I don't care.

1784675108504.gif
 
Updates to 8.1 and 10. Both are EOL and have been.

Actually you can buy extended support for Win 10. They don't advertise this, and I'm not supposed to tell people about it, (at my job). But I'm also not supposed to tell people about Libre Office when they find out that MS Office isn't included with Windows anymore, and you can't buy a perpetual license either. Instead they have to pay $100 for a one year subscription for a single account.

What I do instead show people the Libre office website, tell them to take a picture before I close the window then delete cookies and browsing history.
 
Last edited:
As I have secure boot disabled on my Tower's Motherboard and not using windoze...I don't care.

View attachment 32739

Same here, other than one laptop with windows buried underneath piles of boxes and blankets to keep winblows from listening in. I need to keep for a while. Such a shame too. It's a nice laptop!

Other than to let Linux users they might need to disable Secure Boot if they haven't already, why would we care?
 
Actually you can buy extended support for Win 10.

I know. I've mentioned it many times. It's still EOL. The caveat is that you can pay about $30 per year to keep getting some patches.
 


Follow Linux.org

Members online

No members online now.

Top