Windows 10: Security Update KB5012170

Discus and support Security Update KB5012170 in Windows 10 Gaming to solve the problem; Hi,I work for an organisation with BYO laptops. Recently a very high percentage of laptops are installing KB5012170 and after a reboot are prompted... Discussion in 'Windows 10 Gaming' started by Andrew Warfield, Feb 15, 2023.

  1. Security Update KB5012170


    Hi,I work for an organisation with BYO laptops. Recently a very high percentage of laptops are installing KB5012170 and after a reboot are prompted with a windows login screen. The problem is - this login screen does not contain the previous logged in user, so if the clients cannot remember their original password when they are at the prompt - they cannot login to the laptop, and are basically forced to wipe the laptop to factory defaults. This effects Windows 10 22H2 and Windows 11.What instructions can I give my clients to retrieve their username and reset their most likely blank password,

    :)
     
    Andrew Warfield, Feb 15, 2023
    #1
  2. Brink Win User

    KB5012170: Security update for Secure Boot DBX: August 9, 2022

    Read more: https://support.microsoft.com/en-us/...8-c42bd211bb15
     
    Brink, Feb 15, 2023
    #2
  3. Blue O Win User
    KB5012170: Security update for Secure Boot DBX: August 9, 2022 - Install error - 0x800f0922

    I've been fighting the same issues all day. KB5012170 fails to install with error 0x800f0922. Looking through C:\Windows\Logs\CBS\CBS.log reveals errors pointing to BitLocker (which is a red herring) and Secure Boot (the real culprit).

    I finally got it to install successfully as follows:

    1. Open a cmd.exe or powershell.exe window running as Administrator

    2. dism.exe /online /cleanup-image /restorehealth

    3. sfc /scannow

    4. Reboot

    5. Manually download the MSU appropriate for your Windows version directly from the Microsoft Update Catalog here: Microsoft Update Catalog

    6. Double click the MSU file to install

    This still didn't work for me, but it did clean up the CBS store and allowed me to successfully install the August 2022 Cumulative Update. However, manually installing KB5012170 still failed with the same error as Windows Update in Settings: 0x800f0922

    Next, I also performed these additional steps:

    7. Reboot into UEFI BIOS

    8. Enabled Secure Boot (it was disabled in my case) => Note: This alone didn't work for me. I also needed to do the next step.

    9. Clear Secure Boot keys (i.e. reset the Secure Boot keys to default factory settings)

    10. Save and exit UEFI BIOS

    After this, I repeated Steps 1-6 above and the KB5012170 MSU package successfully installed.

    Not sure if this will work for everyone, but since KB5012170 updates the Secure Boot Forbidden Signature Database (DBX) in UEFI, clearing the old and potentially stale boot keys and resetting to factory defaults allowed the update to install required changes to DBX.

    Motherboard: Asrock Z87 Extreme6/ac
     
    Blue O, Feb 15, 2023
    #3
  4. Security Update KB5012170

    Shawn Brink, Feb 15, 2023
    #4
Thema:

Security Update KB5012170

Loading...
  1. Security Update KB5012170 - Similar Threads - Security Update KB5012170

  2. KB5012170 Secure Boothole is already installed.

    in Windows 10 Installation and Upgrade
    KB5012170 Secure Boothole is already installed.: A few months back, KB5012170 was released to fix a vulnerability in Windows Security Feature Bypass in Secure Boot BootHole. We've installed this fix KB via SCCM and Powershell and confirmed that it is actually installed. However, Tenable is still detecting that the device is...
  3. KB5012170 Secure Boothole is already installed.

    in Windows 10 Gaming
    KB5012170 Secure Boothole is already installed.: A few months back, KB5012170 was released to fix a vulnerability in Windows Security Feature Bypass in Secure Boot BootHole. We've installed this fix KB via SCCM and Powershell and confirmed that it is actually installed. However, Tenable is still detecting that the device is...
  4. KB5012170 Secure Boothole is already installed.

    in Windows 10 Software and Apps
    KB5012170 Secure Boothole is already installed.: A few months back, KB5012170 was released to fix a vulnerability in Windows Security Feature Bypass in Secure Boot BootHole. We've installed this fix KB via SCCM and Powershell and confirmed that it is actually installed. However, Tenable is still detecting that the device is...
  5. Security Update KB5012170

    in Windows 10 Software and Apps
    Security Update KB5012170: Hi,I work for an organisation with BYO laptops. Recently a very high percentage of laptops are installing KB5012170 and after a reboot are prompted with a windows login screen. The problem is - this login screen does not contain the previous logged in user, so if the clients...
  6. Security Update KB5012170

    in Windows Hello & Lockscreen
    Security Update KB5012170: Hi,I work for an organisation with BYO laptops. Recently a very high percentage of laptops are installing KB5012170 and after a reboot are prompted with a windows login screen. The problem is - this login screen does not contain the previous logged in user, so if the clients...
  7. KB5012170 --- secure boot?

    in Windows 10 Gaming
    KB5012170 --- secure boot?: Hello --- there seems to be much written about this fix/patch but what I don't understand why is MS trying to apply this to old computer that are BIOS/MBR units? I just updated an old computer from win7 to win10 22H2 and update tried to apply this patch 2 times and failed ---...
  8. KB5012170 --- secure boot?

    in Windows 10 Software and Apps
    KB5012170 --- secure boot?: Hello --- there seems to be much written about this fix/patch but what I don't understand why is MS trying to apply this to old computer that are BIOS/MBR units? I just updated an old computer from win7 to win10 22H2 and update tried to apply this patch 2 times and failed ---...
  9. KB5012170 --- secure boot?

    in Windows 10 Installation and Upgrade
    KB5012170 --- secure boot?: Hello --- there seems to be much written about this fix/patch but what I don't understand why is MS trying to apply this to old computer that are BIOS/MBR units? I just updated an old computer from win7 to win10 22H2 and update tried to apply this patch 2 times and failed ---...
  10. Update KB5012170 issue

    in Windows 10 Gaming
    Update KB5012170 issue: As the world knows Microsoft update is causing bitlocker issue for many subscribers and there is no way to solve this. I didnt create this bitlocker and in my profile I dont see any bitlocker recovers keys. When I navigate to Manage Bitlocker keys I get "Try a Different URL....