Yes, Microsoft signed the buggy Kaspersky bootloader/rootkit. But there’s a good reason why. And Kaspersky is quite justified in saying the problems w
[See the full post at: The mess behind Microsoft’s yanked UEFI patch KB 4524244]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
The mess behind Microsoft’s yanked UEFI patch KB 4524244
Home » Forums » Newsletter and Homepage topics » The mess behind Microsoft’s yanked UEFI patch KB 4524244
- This topic has 19 replies, 12 voices, and was last updated 3 years, 7 months ago by
anonymous.
AuthorTopicwoody
ManagerViewing 8 reply threadsAuthorReplies-
pHROZEN gHOST
AskWoody Lounger -
woody
Manager
-
dph853
AskWoody PlusScott
AskWoody Lounger-
woody
Manager
Aaron Corey
AskWoody LoungerBased on what I’ve been able to glean so far, the affected HP machines have a feature called “Sure Start”, which appears to be an additional layer of security on top of the normal Secure Boot. One of the features of Sure Start is apparently to detect unauthorized tampering with the secure boot keys. It sounds like the revocation list doesn’t get updated very often, so I wonder if HP’s method for detecting tampering might be flawed in some way?
1 user thanked author for this post.
b
ManagerWhat did Kaspersky do wrong?
Nothing. Other than distributing a Kaspersky Rescue Disk program, prior to August 2019, that could be used for nefarious purposes.Sure. Why should a security vendor follow the rules that would prevent its free image being downloaded to attack any Windows computer?
, but this older version of the Kaspersky Rescue Disk didn’t follow the Secure Boot rules.
Windows 11 Pro version 22H2 build 22621.2361 + Microsoft 365 + Edge
-
MikeFromMarkham
AskWoody Lounger
wavy
AskWoody PlusAs quoted by Woody
Let’s hope the “improved version” works better than the old one — and that it takes less than ten months to respond to the problem. Meanwhile, ValdikSS warns in a tweet:
At least 2 other vuln bootloaders exist, not revoked.
More to come.
🍻
Just because you don't know where you are going doesn't mean any road will get you there.Alex5723
AskWoody PlusYes, Microsoft signed the buggy Kaspersky bootloader/rootkit. But there’s a good reason why
Let me understand :
Every single version (all 1000 ) of live Linux that can boot a PC, every version of backup software that creates a restore media to boot into a PC… and those are (rootkit) bootkit, all are signed by Microsoft as safe ?
-
Aaron Corey
AskWoody LoungerMicrosoft offers to sign third-party bootloaders, and I think a few Linux distros have taken them up on that offer. MS has two private keys they use for signing bootloaders: one for the Windows bootloader and one for third-party operating systems. If your distro or OS of choice isn’t signed by MS, then you have to disable Secure Boot in order to boot it. I think most x86/x64 based PCs allow you to disable secure boot, but ARM-based WinRT devices don’t.
-
woody
Manager
EP
AskWoody_MVPHewlett-Packard has just released a support article regarding the yanked KB4524244 update on affected HP machines:
https://support.hp.com/us-en/product/hp-elitebook-735-g5-notebook-pc/18804892/document/c06572866
1 user thanked author for this post.
-
woody
Manager -
Aaron Corey
AskWoody LoungerThe HP article is interesting… After saying that you can prevent the issue by not installing the update, they also provide recovery steps for those who already installed the update. Their instructions are a bit confusing because there seem to be some details missing. But from the sounds of things, the “Sure Start” feature has some sort of real-time protection that blocks the Windows update process from modifying the revocation list during the reboot. They advise temporarily turning off the “Sure Start Secure Boot keys protection” feature to allow the update to install and then re-enable the protection feature afterwards. That recovery procedure doesn’t contain any steps to uninstall KB4524244 afterwards, so I guess they’re implying it’s okay to leave it installed once you manage to get past the Sure Start protection feature?
-
anonymous
GuestWhy this continuing comedy of errors from MS and are there actual humans in the loop when approving all that is related to Key Signing/Key Authority. And hopefully there will be some more humans upstream with the key vetting/certification process so the end user humans downstream experience less pain.
With that Key Signing Authority comes some very serous Key Signing Responsibility and maybe MS needs to be required to act more like an actual authority and not skimp on the QA/QC is that part of the chain of trust.
Viewing 8 reply threads - This topic has 19 replies, 12 voices, and was last updated 3 years, 7 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
iOS 17 : New Safari Privat Search Engines
by
Alex5723
13 minutes ago -
Photos App running in background
by
Tom
15 hours, 55 minutes ago -
IPV6 Issue Win10 22H2 August Update
by
Win7and10
3 minutes ago -
Windows 11 Insider Preview build 23550 released to DEV
by
joep517
22 hours, 17 minutes ago -
Windows 11 Build 22621.2361 (22H2) released to Release Preview
by
joep517
22 hours, 18 minutes ago -
Lately I’ve been getting qr code spam attacks
by
Susan Bradley
1 day, 1 hour ago -
ghacks Wants Edge – FF Browser Update to View – hack/redirect
by
CraigS26
3 hours, 7 minutes ago -
iOS 17 : If your new iPhone gets stuck on the Apple logo when you transfer…
by
Alex5723
1 day, 9 hours ago -
Apple zero days out – September 2023
by
Susan Bradley
1 day, 4 hours ago -
No shortcuts to files on Taskbar in Win11
by
KingGeorgeN
1 day, 1 hour ago -
“New” Google Sites vs Network Solutions: domain resolution
by
Towson_Steve
11 hours, 56 minutes ago -
Topic: Privacy Report on Modern Cars
by
oldfry
1 day, 14 hours ago -
Microsoft’s massive Windows 11 update, featuring Copilot AI, begins rolling out
by
Alex5723
1 day, 11 hours ago -
MailStore Home updates
by
Alex5723
2 days, 11 hours ago -
T-Mobile users say they see other people’s account information
by
Alex5723
2 days, 22 hours ago -
Retirement of Exchange Web Services in Exchange Online
by
Alex5723
3 days, 11 hours ago -
What Remote Desktop credentials do I use to access a MS Account computer
by
JP
2 days ago -
Office 2003 Compatibility with One Drive in Windows 11
by
langsjw
3 days, 21 hours ago -
Has KB5030219 been pulled for Windows 11 Pro for Workstations?
by
jharri46
1 day ago -
By default encryption on Apple
by
Susan Bradley
3 days, 15 hours ago -
KB5029331 Macrium/Reflect
by
fpefpe
3 days, 16 hours ago -
Windows 10 Build 19045.3513 (22H2) to Release Preview Channel
by
joep517
4 days, 3 hours ago -
Microsoft worker accidentally exposes 38TB of sensitive data in GitHub blunder
by
Nibbled To Death By Ducks
3 days, 13 hours ago -
Change CPU/Mainboard without reinstallation of OS and Apps – Win10
by
schmersa
3 days, 18 hours ago -
Mouse slows to crawl if Edge in focus
by
bryash
4 days, 23 hours ago -
Windows and Surface chief Panos Panay is leaving Microsoft
by
Alex5723
4 days, 12 hours ago -
Essential Office Portable
by
Microfix
5 days, 1 hour ago -
Essential Office: Disable Spell Check
by
Bob Blum
5 days ago -
Apple 2030
by
Will Fastie
12 hours, 31 minutes ago -
Wi-Fi 7? Why not!
by
B. Livingston
1 day, 10 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2023 by AskWoody Tech LLC. All Rights Reserved.