Windows Update KB KB4535680 failed to install to Server 2016 PowerEdge R540
Windows Update KB KB4535680 failed to install to Server 2016 PowerEdge R540
Microsoft Advised
This security update makes improvements to Secure Boot DBX for the supported Windows versions listed in the "Applies to" section. Key changes include the following:
Windows devices that has Unified Extensible Firmware Interface (UEFI) based firmware can run with Secure Boot enabled. The Secure Boot Forbidden Signature Database (DBX) prevents UEFI modules from loading. This update adds modules to the DBX.
A security feature bypass vulnerability exists in secure boot. An attacker who successfully exploited the vulnerability might bypass secure boot and load untrusted software.
This security update addresses the vulnerability by adding the signatures of the known vulnerable UEFI modules to the DBX.
Issue
Workaround
Some original equipment manufacturer (OEM) firmware might not allow for the installation of this update.
Same issue with Server 2019 on all PowerEdge R540. Servers all have latest available BIOS of 2.9.3. Update KB4535680 will not install on any R540. Windows Update reports 0x800f0922. Error in CBS log of
Error TRUST_E_NOSIGNATURE originated in function Windows::WCP::SecureBoot::BasicInstaller::Install expression: ApplySecureBootUpdate( dwAvailableUpdates)
We have the same issue with our T640 servers on Windows Server 2019, also with the latest BIOS version 2.9.4. The Update fails on installation process, we have hidden the updates for the moment, so our servers don't spam with error messages.
I am having the same problem with our Dell R440 Ready Nodes running Server 2019 and a R330 running Server 2016. I get the same error in the CBS log. I have other equipment that installed the update fine in the same environment but the ones that error out are all Dells. It is becoming a bigger problem as it is interfering with other patches when it rolls back the failure and you cannot skip or hide the update. The update has been unsuccessful for a month now, someone please look into this before too many vulnerabilities go unpatched.
snruebes
13 Posts
11758
0
Posted February 12th, 2021 03:00
Same here - no help - neither from DELL nor from Microsoft!
I assume Dell missed to release a compatible BIOS version....