- Joined
- Oct 17, 2017
tl;dr do not install KB 5012170 (even blacklist) if you have any "untrusted" UEFI blobs in your system.
Spent the last two days figuring out why some systems all of a sudden boot up to a black screen.
Talked to a Microsoft dev, which I got the contact through a rep at work and according to him, some pajeets fucked up the logic on checking for GOP versioning and UEFI support for dGPU's.
From what I understand, the update only installs if your GPU is on the list of ones with factory UEFI support. Then, regardless of the result, it checks whether the GOP version is newer than 2.0.0.0.
Somehow, if the first check returns a negative, and the other doesn't return null - it still installs it and ince some machines we have contain older GPU's with modded GOP drivers in their vbios, they just boot to a black screen and eventually get a VIDEO_TDR_FAILURE or CRITICAL_PROCESS_DIED BSOD.
AFAIK, this can happen to other PCIe controllers, like network and storage ones. Hopefully this saves someone some trouble.
support.microsoft.com
I've already submitted a Microsoft Bug Bounty form, but from past history, I can't say I'm expecting much.
Spent the last two days figuring out why some systems all of a sudden boot up to a black screen.
Talked to a Microsoft dev, which I got the contact through a rep at work and according to him, some pajeets fucked up the logic on checking for GOP versioning and UEFI support for dGPU's.
From what I understand, the update only installs if your GPU is on the list of ones with factory UEFI support. Then, regardless of the result, it checks whether the GOP version is newer than 2.0.0.0.
Somehow, if the first check returns a negative, and the other doesn't return null - it still installs it and ince some machines we have contain older GPU's with modded GOP drivers in their vbios, they just boot to a black screen and eventually get a VIDEO_TDR_FAILURE or CRITICAL_PROCESS_DIED BSOD.
AFAIK, this can happen to other PCIe controllers, like network and storage ones. Hopefully this saves someone some trouble.
KB5012170: Security update for Secure Boot DBX: August 9, 2022

I've already submitted a Microsoft Bug Bounty form, but from past history, I can't say I'm expecting much.