apply the Microsoft Windows UEFI CA 2023

Jim Whitaker 221 Reputation points
2025-10-26T19:29:58.4733333+00:00

I am confused on the Microsoft Windows UEFI CA 2023. There are instructions at the bottom of page:

https://techcommunity.microsoft.com/blog/windows-itpro-blog/updating-microsoft-secure-boot-keys/4055324

However am I suppose to do what is in this link first:

https://support.microsoft.com/en-us/topic/how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d

Can someone let me know if both is needed or just one of these, and which one. Also if both, which do I do first.

Then can someone tell me after doing the above does the new 2023 boot files transfer to:

C:\Windows\Boot\EFI or are you suppose to manually do this, if manually is there an article explaining what and how?

I'd like to go ahead with this but the instructions are not detailed.

Windows for home | Windows 11 | Windows update
0 comments No comments

Answer accepted by question author
Huy-K 13,985 Reputation points Microsoft External Staff Moderator
2025-11-07T03:51:17.8066667+00:00

Dear @Jim Whitaker,

Thank you for posting your question in the Microsoft Q&A forum.

Based on your description:

There are two separate but related actions:

  1. Update secure boot certificates (Windows UEFI CA 2023): This step ensures your devices trust the new 2023 certificates before the older ones expire in 2026. Microsoft is delivering these updates through Windows Update and OEM firmware. We recommend applying the latest firmware and Windows updates first, then verifying that the new certificates are present.
  2. Manage boot manager revocations: This addresses CVE‑2023‑24932 by revoking vulnerable boot managers. It should only be implemented after confirming your devices have the new certificates and your boot media is updated. Revocations are irreversible while Secure Boot is enabled, so pilot testing is strongly advised before broad deployment.

Recommended Order:

You should start with the TechCommunity blog steps to apply the new certificate. Once that’s successfully applied and verified, you can proceed with the revocation steps from the CVE article if your environment requires it.

In short:

  • Apply the new certificate first (TechCommunity blog).
  • Then manage revocations if needed (CVE support article).

Notes:

  • You do not need to manually copy files to C:\Windows\Boot\EFI. These updates are applied via Windows Update and firmware updates.
  • If you manage custom boot or imaging media, rebuild them with the latest tools and boot loaders before enabling revocations.

If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment". 

Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

User's image

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.