In This Article
After nine months of frustration for dual-boot users, Microsoft released an out-of-band patch on May 14 that resolves the Secure-Boot revocation issue introduced by the August 2024 cumulative updates. BleepingComputer
What Happened?
The August patch updated Secure Boot’s SBAT revocation list to block vulnerable GRUB2 bootloaders (CVE-2022-2601). Unfortunately, many Linux distributions still signed with the shim,3 or GRUB,3 identifiers, causing Secure Boot to refuse them. BleepingComputer
Who Was Affected?
- Windows 10 & 11 dual-boot laptops and desktops
- Windows Server 2012 R2 – 2022 hosting Hyper-V Gen-2 VMs with Linux guests
- Any environment with Secure Boot enabled and outdated Linux shims
The Fix
Install KB5039213 (or the equivalent monthly roll-up). The update:
- Re-signs trusted shims and bootloaders.
- Rolls back the problematic SBAT policies.
- Adds telemetry to catch future breakage.
ECS Recommendations
Step | Action | Notes |
1 | Patch ASAP via WSUS or Intune. | Schedule reboot windows. |
2 | Re-enable Secure Boot if previously disabled. | Verify boot order first. |
3 | Check shim versions on Debian/Ubuntu (should be shim,4 or newer). | Use mokutil --sb-state. |
4 | Document BIOS settings post-update. | Capture screenshots for audit. |
Need help? Contact ECS Support—our team can validate your dual-boot fleet remotely.