Dear @Jim Whitaker,
Thank you for posting your question in the Microsoft Q&A forum.
Based on your description:
There are two separate but related actions:
- Update secure boot certificates (Windows UEFI CA 2023): This step ensures your devices trust the new 2023 certificates before the older ones expire in 2026. Microsoft is delivering these updates through Windows Update and OEM firmware. We recommend applying the latest firmware and Windows updates first, then verifying that the new certificates are present.
- Manage boot manager revocations: This addresses CVE‑2023‑24932 by revoking vulnerable boot managers. It should only be implemented after confirming your devices have the new certificates and your boot media is updated. Revocations are irreversible while Secure Boot is enabled, so pilot testing is strongly advised before broad deployment.
Recommended Order:
You should start with the TechCommunity blog steps to apply the new certificate. Once that’s successfully applied and verified, you can proceed with the revocation steps from the CVE article if your environment requires it.
In short:
- Apply the new certificate first (TechCommunity blog).
- Then manage revocations if needed (CVE support article).
Notes:
- You do not need to manually copy files to C:\Windows\Boot\EFI. These updates are applied via Windows Update and firmware updates.
- If you manage custom boot or imaging media, rebuild them with the latest tools and boot loaders before enabling revocations.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.