Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

BlackLotus could bypass Secure Boot on a Windows system with current Windows patches because fixing the vulnerable code did not automatically revoke older, vulnerable boot managers that were still validly signed. Microsoft’s mitigation is to revoke those boot managers—a separate security change that must be deliberately deployed and tested. The flaw was not literally unpatchable: the distinction is between patching code and withdrawing trust from vulnerable boot files.

What the Secure Boot bypass was

The malware most closely associated with the headline is BlackLotus, a UEFI bootkit that exploited CVE-2022-21894, also known as Baton Drop. ESET researchers reported in 2023 that Microsoft had fixed the vulnerability in a January 2022 update, but affected, validly signed binaries had not yet been added to the UEFI revocation list. BlackLotus brought copies of those vulnerable binaries to a target and used them to get around Secure Boot. ESET’s BlackLotus analysis explains this gap.

Microsoft tracks the later mitigation for this Secure Boot bypass as CVE-2023-24932. Microsoft’s boot-manager revocation guidance says the corrective protection requires revoking vulnerable boot managers. That is why descriptions of an “unpatchable” flaw are misleading: Windows code was patched, but patching alone did not remove the older signed files from the set of boot applications the device trusted.

Why Secure Boot did not block a vulnerable signed file

UEFI firmware starts boot applications and uses Secure Boot to check their signatures against firmware trust and revocation databases. Windows Trusted Boot continues the chain by verifying the Windows kernel and startup components. The chain is only as strong as the boot applications and trust decisions at its beginning. A signed boot manager can still pass Secure Boot if its signature or version has not been revoked, even when a newer version fixes a vulnerability in its code. Microsoft describes the Windows boot chain in its guide to securing the Windows boot process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

In other words, a Windows update that fixes vulnerable code and a Secure Boot revocation that prevents an old boot manager from loading solve different parts of the problem. The latter changes what firmware is willing to trust.

What BlackLotus could do—and what access it required

Microsoft’s investigation describes a chain in which BlackLotus wrote malicious files to the EFI System Partition, enrolled the attacker’s Machine Owner Key for persistence, disabled Hypervisor-protected Code Integrity (HVCI), deployed a malicious kernel driver, used that driver to run an HTTP downloader, and disabled BitLocker and Microsoft Defender. These are capabilities documented in Microsoft’s account of BlackLotus activity; they should not be read as a claim that every infection follows an identical sequence.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Microsoft says exploitation requires administrative privileges or physical access to the device. Its guidance does not describe this as an unauthenticated remote attack that can begin from any internet host. The risk is that an attacker with sufficient access can use the boot-chain weakness to establish or extend control beneath the operating system.

Does installing Windows updates enable the mitigation?

No. Microsoft says Windows security updates released on July 9, 2024, and later include CVE-2023-24932 mitigations, but the mitigations are not enabled by default. Installing updates is necessary, but an administrator must still evaluate and enforce the relevant protections. Check Microsoft’s current support guidance for the applicable Windows versions and deployment instructions rather than relying on an old version list.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How administrators should plan revocation

Revocation changes which boot managers a device will accept, so it can affect more than a Windows installation. Microsoft’s enterprise deployment guidance describes a staged approach. Before broad enforcement, account for firmware behavior, recovery options, BitLocker, and any non-Windows boot dependencies.

  1. Install applicable Windows security updates. Use Microsoft’s live affected-version and update guidance for the specific Windows releases in your environment.
  2. Inventory and group device types. Separate representative hardware and firmware classes, and identify systems that rely on PXE, dual boot, older installation media, or custom recovery processes.
  3. Test on representative devices before enforcing broadly. Confirm that Secure Boot database changes are processed correctly and that normal startup, recovery, and required boot workflows still work.
  4. Prepare recovery access. Keep BitLocker recovery keys available and update installation and recovery media. Media that depends on a revoked boot manager may no longer start.
  5. Enforce the mitigations using Microsoft’s instructions. Follow the current procedure for the specific device and Windows version; do not assume that installing the update performed this step automatically.
  6. Verify the result and retain a recovery route. Check that devices boot as expected after enforcement. If firmware cannot update the Secure Boot database or DBX, Microsoft advises contacting the device manufacturer about relevant firmware updates.

Certificate migration is related operational work, but certificate authorities have different roles and should not be treated as interchangeable. Microsoft’s 2025 enterprise guidance listed October 2026 as the expiration date for the Microsoft Windows Production PCA 2011 certificate, whose replacement for signing Windows boot applications is Windows UEFI CA 2023. It separately listed July 2026 expiration dates for Microsoft Corporation KEK CA 2011 and Microsoft Corporation UEFI CA 2011, with corresponding 2023 replacements. Because those dates are now at or past their stated deadlines, administrators should check Microsoft’s current guidance and device firmware status rather than infer from the dates alone whether a device has completed the transition.

Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Microsoft’s current support guidance also includes compatibility information tied to updates released on or after April 2026: on TPM 2.0-based Windows Server 2012 and 2012 R2 systems, mitigation support changes, and Secure Version Number 5.0 can invalidate older external boot media after PCA 2011 revocations if that media was not built with updates released on or before January 2025. Confirm the current details in Microsoft’s support article before deploying or rebuilding media.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to look for when investigating a suspected infection

Microsoft identifies recently modified and locked bootloader files in the EFI System Partition as suspicious indicators, including winload.efi, bootmgfw.efi, and grubx64.efi in the boot path it describes. In that scenario, an attempt to access a locked file may return ERROR_SHARING_VIOLATION. These are investigation leads, not proof of BlackLotus by themselves.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Microsoft Defender Antivirus detections named in the investigation include Trojan:Win32/BlackLotus and Trojan:Win64/BlackLotus.
  • Microsoft Defender for Endpoint may alert on known BlackLotus or post-exploitation activity, including “Possible vulnerable EFI bootloader.”
  • These detections cover known samples or activity and are not a guarantee that every compromise will be detected.

If these indicators are found, Microsoft advises isolating the device from the network and investigating for BlackLotus or follow-on activity. For a device that is already compromised, Microsoft recommends contacting a security provider. See Microsoft’s investigation guidance and its mitigation guidance.

A separate issue: vulnerable third-party UEFI bootloaders

BlackLotus is not the only reason Secure Boot revocation matters, but other cases should not be conflated with CVE-2022-21894. CERT/CC’s VU#309662 covers three specific Microsoft-signed third-party UEFI bootloaders that could allow a Secure Boot bypass through a custom installer or EFI shell:

Bootloader vendor Vulnerability
New Horizon Datasys CVE-2022-34302
CryptoPro Secure Disk CVE-2022-34301
Eurosoft CVE-2022-34303

CERT/CC warns that unsigned code could execute before operating-system startup in those cases. This is a distinct group of bootloader vulnerabilities, not evidence that all signed bootloaders—or every Secure Boot device—are vulnerable.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.