News: 1660575854

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft's Secure Boot fix sends some PCs into BitLocker Recovery

(2022/08/15)


Windows users are reporting BitLocker problems after installing last week's security update for Secure Boot.

The issues are related to [1]KB5012170 , which is designed to plug some Secure Boot holes. It's important for users running kit with Unified Extensible Firmware Interface (UEFI) firmware. "A security feature bypass vulnerability exists in secure boot," wrote Microsoft. "An attacker who successfully exploited the vulnerability might bypass secure boot and load untrusted software."

The patch adds the signatures of the known vulnerable UEFI modules to the Secure Boot Forbidden Signature Database (DBX).

[2]

Alas, it appears to do a bit more than that. Lurking in the known issues are warnings that some OEM firmware won't allow the update to be installed. The update might also fail to install with certain BitLocker Group Policy configurations or an 0x800f0922 might be thrown up.

[3]

[4]

Then there is the tripping of BitLocker recovery, which is not currently listed as a known issue.

The problem occurs on boot, and bring up the BitLocker Recovery screen into which a user is supposed to enter a key.

[5]

The depressingly familiar [6]groundswell of grumbling has got under way as a few users have found themselves with unbootable computers unless they can provide the magic key.

[7]

A screenshot sent to us by a reader

Register reader Anthony got in touch to tell us that out of the 400 PCs his company managed, 2 percent (all Windows 11) booted to a BitLocker recovery screen after the update.

[8]Microsoft's fix for 'data damage' risk hits PC performance

[9]AMD confirms Ryzen chips' stuttering performance on Windows 10, 11

[10]User locked out of Microsoft account by MFA bug, complains of customer-hostile support

[11]Azure flings out free virtual trusted platform module for cloudy VMs

"There is seemingly no way around it if the user doesn't have the key, which is the case most of the time!"

BitLocker is a drive encryption feature aimed at keeping data secure. The recovery process restores access to data and requires the user to supply a lengthy password (or a domain administrator can get the password via Active Directory Domain Services). Anthony told us he was able to log into Azure and retrieve the recovery keys.

"This is the sort of thing the average user would certainly not be able to do," he said. "For some of them it was easy, for others it was a detective game to find out which licence was assigned to which computer."

As for what the patch did to cause the problem, there are a variety of candidates (if one discounts attack attempts). One potential cause listed by Microsoft in its BitLocker [12]documentation is "upgrading critical early startup components, such as a BIOS or UEFI firmware upgrade, causing the related boot measurements to change."

[13]

The Register asked Microsoft for an explanation and will update should the company respond.

In the meantime, it would probably be worth at least knowing how to get hold of your recovery key before hitting the update button. Just in case. ®

Get our [14]Tech Resources



[1] https://support.microsoft.com/en-gb/topic/kb5012170-security-update-for-secure-boot-dbx-august-9-2022-72ff5eed-25b4-47c7-be28-c42bd211bb15

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YvptoQbTBDhx9Fn4djQq1gAAAI0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YvptoQbTBDhx9Fn4djQq1gAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YvptoQbTBDhx9Fn4djQq1gAAAI0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YvptoQbTBDhx9Fn4djQq1gAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.reddit.com/r/pcmasterrace/comments/wkqkmg/is_the_windows_update_kb5012170_safe_to_install/

[7] https://regmedia.co.uk/2022/08/15/bitlocker_redacted.jpg

[8] https://www.theregister.com/2022/08/09/widows_data_damage/

[9] https://www.theregister.com/2022/03/08/amd_stutter/

[10] https://www.theregister.com/2021/10/12/user_locked_out_of_microsoft/

[11] https://www.theregister.com/2021/03/09/azure_vtpm_trusted_launch_preview/

[12] https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-recovery-guide-plan

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YvptoQbTBDhx9Fn4djQq1gAAAI0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



Grabs popcorn ...

Anonymous Coward

So how will MS fix this without asking the user to do it for them (at a cost of house @ $/hour) ?

This is (yet) another reason to have your MS estate handled under a managed contract. Get the poor middleman to suck up the cost.

I did this last year with their printing fuckup. Took pretty much a man-day for 50 machines.

My personal approach is to stop them at "What you need to do" and reflect it back to them :

No:,. what *you* need to do .... (is fix your shit).

Kev99

Ah, once more mictosoft shows off its great quality control and product testing.

Quality control

anthonyhegedus

It’s the total lack of quality control paired with a total lack of transparency. The Microsoft page about the update doesn’t list this as a known problem but they MUST have known about it, surely? Surely…?

Why are these machines being encrypted anyway? I’ve seen several machines fail to boot with this message, and yet the user has no recollection of ever encrypting the drive. What do you do if you only have one computer and can’t log in to Microsoft to retrieve the key?

Yes, it all comes back to quality control. This is something that Microsoft has let lapse for far too long that we are accustomed to we just expect this sort of bullshit.

Sudosu

Microsoft, protecting us from "untrusted" software....something something irony.

So... ummmm...

aerogems

If a person cannot get into their PC, how are they supposed to go to the URLs in the error screen? One shouldn't assume that everyone has a cell phone with Internet access that they could use in a pinch. Given the news coming out about a former occupant of the White House, what about people who work inside secure facilities and are expected to surrender their devices before entering?

A dwarf is passing out somewhere in Detroit!