re KB4524244 and the UEFI ‘patch’ I may be WAY WAY off base here but here goes: the
“UEFI boot manager ” referenced is not the firmware applications supplied by Motherboard manufacturers but the part that gets installed by an OS setup program when it is installing the OS. That would be in part a “BootOrder variable” that directs the firmware where to find the applicable EFI file ( \EFI\boot\bootx64.efi for Windows 64 bit various other places for other OSs ). I do not know but there must be safe guards to prevent a non SecureBoot when one is called for. I recall the problems Linux users had booting when this SecureBoot stuff started years ago with having a valid signed boot code to boot and only MS certs shipping with MotherBoards. So I ask is the new patch just adjusting the “BootOrder variable” implimentation that is put in by the OS in the first place?
🍻
Just because you don't know where you are going doesn't mean any road will get you there.