{"id":2356,"date":"2023-07-12T02:00:31","date_gmt":"2023-07-11T17:00:31","guid":{"rendered":"https:\/\/m365jp.xyz\/?p=2356"},"modified":"2023-07-12T02:05:35","modified_gmt":"2023-07-11T17:05:35","slug":"mc637454-take-action-july-11-2023-starts-the-second-deployment-phase-to-address-cve-2023-24932-for-devices-using-secure-boot","status":"publish","type":"post","link":"https:\/\/m365jp.net\/index.php\/2023-07-12-mc637454-take-action-july-11-2023-starts-the-second-deployment-phase-to-address-cve-2023-24932-for-devices-using-secure-boot","title":{"rendered":"MC637454 | Take action: July 11, 2023 starts the Second Deployment Phase to address CVE-2023-24932 for devices using Secure Boot"},"content":{"rendered":"<div class=\"postie-post\">\n<div>\n<hr>\n<table id=\"section\">\n<tbody>\n<tr>\n<th width=\"95%\">MC637454 | Take action: July 11, 2023 starts the Second Deployment Phase to address CVE-2023-24932 for devices using Secure Boot<\/th>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr>\n<table id=\"data\">\n<tbody>\n<tr>\n<th>Classification<\/th>\n<td>preventOrFixIssue<\/td>\n<\/tr>\n<tr>\n<th>Last Updated<\/th>\n<td>07\/11\/2023 16:56:40<\/td>\n<\/tr>\n<tr>\n<th>Start Time<\/th>\n<td>07\/11\/2023 16:56:32<\/td>\n<\/tr>\n<tr>\n<th>End Time<\/th>\n<td>07\/11\/2024 16:56:32<\/td>\n<\/tr>\n<tr>\n<th>Message Content<\/th>\n<td>\n<div>The release of the July 11, 2023 security updates for Windows starts the Second Deployment Phase in  <a href=\"https:\/\/support.microsoft.com\/help\/5025885\" rel=\"noopener noreferrer\" target=\"_blank\">  KB5025885: How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932<\/a>.  <a href=\"https:\/\/support.microsoft.com\/help\/5025885\" rel=\"noopener noreferrer\" target=\"_blank\">  KB5025885<\/a> contains the manual steps to verify your environment is ready for the changes and steps to enable the security hardening changes to protect against vulnerabilities tracked by  <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-24932\" rel=\"noopener noreferrer\" target=\"_blank\">  CVE-2023-24932<\/a> that can bypass the Secure Boot security feature using the BlackLotus UEFI bootkit.<\/div>\n<div>  <\/div>\n<div>The Second Deployment Phase in updates for Windows released July 11, 2023 and later add the following:<\/div>\n<ul>\n<li>Allow easier, automated deployment of the revocation files (Code Integrity Boot policy and Secure Boot disallow list (DBX)).<\/li>\n<li>New Event Log events will be available to report whether revocation deployment was successful or not.<\/li>\n<li>SafeOS dynamic update package for Window Recovery Environment (WinRE).<\/li>\n<\/ul>\n<div>&nbsp;&nbsp;<\/div>\n<div><b>When will this happen:<\/b>&nbsp;<\/div>\n<div>Updates released July 11, 2023 and later start the Second Deployment Phase, containing the additional Event Log events to aid in getting your environment ready to enable protections required to address  <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-24932\" rel=\"noopener noreferrer\" target=\"_blank\">  CVE-2023-24932<\/a>. The security hardening for <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-24932\" rel=\"noopener noreferrer\" target=\"_blank\">  CVE-2023-24932<\/a> will be done in phases, as steps must be taken to prevent issues on your organization&#8217;s devices when the revocations are applied\/enabled.&nbsp;The security hardening changes to protect against vulnerabilities tracked by  <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-24932\" rel=\"noopener noreferrer\" target=\"_blank\">  CVE-2023-24932<\/a> have been in updates released May 9, 2023 and later.<\/div>\n<div>&nbsp;&nbsp;<\/div>\n<div><b>What you need to do to prepare:<\/b>&nbsp;<\/div>\n<div>For information on how to enable the revocations and what is required before you should enable the revocations, see  <a href=\"https:\/\/support.microsoft.com\/help\/5025885\" rel=\"noopener noreferrer\" target=\"_blank\">  KB5025885: How to manage the Windows Boot Manager revocations for Secure Boot changes associated with CVE-2023-24932<\/a>.&nbsp;<\/div>\n<\/td>\n<\/tr>\n<tr>\n<th>Machine Translation<\/th>\n<td>\n<div>2023\u5e747\u670811\u65e5\u306eWindows\u7528\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u306e\u30ea\u30ea\u30fc\u30b9\u306b\u3088\u308a\u3001 <a href=\"https:\/\/support.microsoft.com\/help\/5025885\" rel=\"noopener noreferrer\" target=\"_blank\">  KB5025885\u306e\u7b2c2\u5c55\u958b\u30d5\u30a7\u30fc\u30ba\u304c\u958b\u59cb\u3055\u308c\u307e\u3059:CVE-2023-24932\u306b\u95a2\u9023\u3059\u308b\u30bb\u30ad\u30e5\u30a2\u30d6\u30fc\u30c8\u306e\u5909\u66f4\u306b\u5bfe\u3059\u308bWindows\u30d6\u30fc\u30c8\u30de\u30cd\u30fc\u30b8\u30e3\u30fc\u306e\u5931\u52b9\u3092\u7ba1\u7406\u3059\u308b\u65b9\u6cd5<\/a>\u3002  <a href=\"https:\/\/support.microsoft.com\/help\/5025885\" rel=\"noopener noreferrer\" target=\"_blank\">  KB5025885<\/a> \u306b\u306f\u3001\u74b0\u5883\u304c\u5909\u66f4\u306e\u6e96\u5099\u304c\u3067\u304d\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3059\u308b\u305f\u3081\u306e\u624b\u52d5\u306e\u624b\u9806\u3068\u3001BlackLotus UEFI\u30d6\u30fc\u30c8\u30ad\u30c3\u30c8\u3092\u4f7f\u7528\u3057\u3066\u30bb\u30ad\u30e5\u30a2\u30d6\u30fc\u30c8\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd\u3092\u30d0\u30a4\u30d1\u30b9\u3067\u304d\u308b  <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-24932\" rel=\"noopener noreferrer\" target=\"_blank\">  CVE-2023-24932<\/a> \u306b\u3088\u3063\u3066\u8ffd\u8de1\u3055\u308c\u305f\u8106\u5f31\u6027\u304b\u3089\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5f37\u5316\u306e\u5909\u66f4\u3092\u6709\u52b9\u306b\u3059\u308b\u624b\u9806\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/div>\n<div>  <\/div>\n<div>2023 \u5e74 7 \u6708 11 \u65e5\u4ee5\u964d\u306b\u30ea\u30ea\u30fc\u30b9\u3055\u308c\u305f Windows \u7528\u306e\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u306e\u7b2c 2 \u5c55\u958b\u30d5\u30a7\u30fc\u30ba\u3067\u306f\u3001\u4ee5\u4e0b\u304c\u8ffd\u52a0\u3055\u308c\u307e\u3059\u3002<\/div>\n<ul>\n<li>\u5931\u52b9\u30d5\u30a1\u30a4\u30eb (\u30b3\u30fc\u30c9\u6574\u5408\u6027\u30d6\u30fc\u30c8 \u30dd\u30ea\u30b7\u30fc\u3068\u30bb\u30ad\u30e5\u30a2 \u30d6\u30fc\u30c8\u7981\u6b62\u30ea\u30b9\u30c8 (DBX)) \u306e\u5c55\u958b\u3092\u5bb9\u6613\u306b\u3057\u307e\u3059\u3002<\/li>\n<li>\u65b0\u3057\u3044\u30a4\u30d9\u30f3\u30c8 \u30ed\u30b0 \u30a4\u30d9\u30f3\u30c8\u3092\u4f7f\u7528\u3057\u3066\u3001\u5931\u52b9\u306e\u5c55\u958b\u304c\u6210\u529f\u3057\u305f\u304b\u3069\u3046\u304b\u3092\u5831\u544a\u3067\u304d\u307e\u3059\u3002<\/li>\n<li>\u30a6\u30a3\u30f3\u30c9\u30a6\u56de\u5fa9\u74b0\u5883 (WinRE) \u7528\u306e SafeOS \u52d5\u7684\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0 \u30d1\u30c3\u30b1\u30fc\u30b8\u3002<\/li>\n<\/ul>\n<div>&nbsp;&nbsp;<\/div>\n<div><b>\u3053\u308c\u306f\u3044\u3064\u8d77\u3053\u308a\u307e\u3059\u304b:<\/b>&nbsp;<\/div>\n<div>2023 \u5e74 7 \u6708 11 \u65e5\u306b\u30ea\u30ea\u30fc\u30b9\u3055\u308c\u305f\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u4ee5\u964d\u3067\u306f\u3001 <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-24932\" rel=\"noopener noreferrer\" target=\"_blank\">  CVE-2023-24932<\/a> \u306b\u5bfe\u51e6\u3059\u308b\u305f\u3081\u306b\u5fc5\u8981\u306a\u4fdd\u8b77\u3092\u6709\u52b9\u306b\u3059\u308b\u305f\u3081\u306b\u74b0\u5883\u3092\u6e96\u5099\u3059\u308b\u306e\u306b\u5f79\u7acb\u3064\u8ffd\u52a0\u306e\u30a4\u30d9\u30f3\u30c8 \u30ed\u30b0 \u30a4\u30d9\u30f3\u30c8\u3092\u542b\u3080\u3001\u7b2c 2 \u5c55\u958b\u30d5\u30a7\u30fc\u30ba\u304c\u958b\u59cb\u3055\u308c\u307e\u3059\u3002  <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-24932\" rel=\"noopener noreferrer\" target=\"_blank\">  CVE-2023-24932<\/a> \u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5f37\u5316\u306f\u6bb5\u968e\u7684\u306b\u884c\u308f\u308c\u307e\u3059, \u5931\u52b9\u304c\u9069\u7528\/\u6709\u52b9&nbsp;\u306b\u306a\u3063\u305f\u3068\u304d\u306b\u7d44\u7e54\u306e\u30c7\u30d0\u30a4\u30b9\u3067\u306e\u554f\u984c\u3092\u9632\u3050\u305f\u3081\u306e\u624b\u9806\u3092\u5b9f\u884c\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u305f\u3081.  <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-24932\" rel=\"noopener noreferrer\" target=\"_blank\">  CVE-2023-24932<\/a> \u306b\u3088\u3063\u3066\u8ffd\u8de1\u3055\u308c\u305f\u8106\u5f31\u6027\u304b\u3089\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5f37\u5316\u306e\u5909\u66f4\u306f\u30012023\u5e745\u67089\u65e5\u4ee5\u964d\u306b\u30ea\u30ea\u30fc\u30b9\u3055\u308c\u305f\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u306b\u542b\u307e\u308c\u3066\u3044\u307e\u3059\u3002<\/div>\n<div>&nbsp;&nbsp;<\/div>\n<div><b>\u6e96\u5099\u3059\u308b\u305f\u3081\u306b\u5fc5\u8981\u306a\u3053\u3068:<\/b>&nbsp;<\/div>\n<div>\u5931\u52b9\u3092\u6709\u52b9\u306b\u3059\u308b\u65b9\u6cd5\u3068\u3001\u5931\u52b9\u3092\u6709\u52b9\u306b\u3059\u308b\u524d\u306b\u5fc5\u8981\u306a\u3082\u306e\u306b\u3064\u3044\u3066\u306f\u3001\u300c <a href=\"https:\/\/support.microsoft.com\/help\/5025885\" rel=\"noopener noreferrer\" target=\"_blank\">  KB5025885: CVE-2023-24932 \u306b\u95a2\u9023\u3059\u308b\u30bb\u30ad\u30e5\u30a2 \u30d6\u30fc\u30c8\u306e\u5909\u66f4\u306b\u5bfe\u3059\u308b Windows \u30d6\u30fc\u30c8 \u30de\u30cd\u30fc\u30b8\u30e3\u30fc\u306e\u5931\u52b9\u3092\u7ba1\u7406\u3059\u308b\u65b9\u6cd5<\/a>\u300d\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002&nbsp;<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>MC637454 | Take action: July 11, 2023 starts the Second Deployment Phase to address CVE-2023-24932 for devices [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2356","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/2356","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/comments?post=2356"}],"version-history":[{"count":0,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/2356\/revisions"}],"wp:attachment":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/media?parent=2356"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/categories?post=2356"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/tags?post=2356"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}