TPM lockout occurs unexpectedly in Windows 8.1 or Windows RT 8.1

This article describes an issue in which Trusted Platform Module (TPM) lockout occurs unexpectedly in Windows 8.1, Windows RT 8.1, or Windows Server 2012 R2. An update is available to fix this issue. Before you install this update, see the Prerequisites section.

Note This update is re-released on October 13, 2015, with a smaller boot loader file bootmgfw.efi.
Symptoms
When this issue occurs, applications that depend on TPM won't function until you reset the TPM lockout.

Note You can enter a 48-digit BitLocker recovery key to continue using the computer after TPM is locked out.
Cause
When the start command is received without a prior shutdown command, the lockout count increments. This causes the TPM lockout to occur if you turn on the device accidentally and repeatedly.
How to get this update
Important If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.

Method 1: Windows Update

This update is provided as an Optional update on Windows Update. For more information about how to run Windows Update, see How to get an update through Windows Update.

Method 2: Microsoft Download Center

The following files are available for download from the Microsoft Download Center:
Operating systemUpdate
All supported x86-based versions of Windows 8.1DownloadDownload the package now.
All supported x64-based versions of Windows 8.1 DownloadDownload the package now.
All supported x64-based versions of Windows Server 2012 R2DownloadDownload the package now.
Note The update for Windows RT 8.1 can be got only from Windows Update.

For more information about how to download Microsoft support files, click the following article number to view the article in the Microsoft Knowledge Base:
119591 How to get Microsoft support files from online services
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help prevent any unauthorized changes to the file.

Update detail information

Prerequisites

To install this update, install April 2014, update rollup for Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2 (2919355) in Windows 8.1 or Windows Server 2012 R2.

Registry information

To apply this update, you don't have to make any changes to the registry.

Restart requirement

You may have to restart the computer after you apply this update.

Update replacement information

This update doesn't replace a previously released update.

File information

The global version of this update installs files that have the attributes that are listed in the following tables. The dates and the times for these files are listed in Coordinated Universal Time (UTC). The dates and the times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and the times may change when you perform certain operations on the files.

Windows 8.1 and Windows Server 2012 R2 file information and notes


  • The files that apply to a specific product, milestone (RTM, SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table:
    VersionProductMilestoneService branch
    6.3.960 0.17 xxxWindows RT 8.1, Windows 8.1, and Windows Server 2012 R2RTMGDR
    6.3.960 0.18 xxxWindows RT 8.1, Windows 8.1, and Windows Server 2012 R2RTMGDR
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.
  • The MANIFEST files (.manifest) and the MUM files (.mum) that are installed for each environment are listed separately in the "Additional file information" section. MUM, MANIFEST, and the associated security catalog (.cat) files, are very important to maintain the state of the updated components. The security catalog files, for which the attributes aren't listed, are signed with a Microsoft digital signature.
For all supported x86-based versions of Windows 8.1
File nameFile versionFile sizeDateTimePlatform
Winresume.efi6.3.9600.180061,269,07206-Aug-201518:23Not applicable
Winresume.exe6.3.9600.180061,168,92006-Aug-201518:23x86
Winload.efi6.3.9600.180061,388,93606-Aug-201518:23Not applicable
Winload.exe6.3.9600.180061,277,88806-Aug-201518:23x86
Wdsmgfw.efi6.3.9600.180061,255,75206-Aug-201518:40Not applicable
Bootmgfw.efi6.3.9600.180061,357,12806-Aug-201518:24Not applicable
Bootmgr.efi6.3.9600.180061,352,53606-Aug-201518:24Not applicable
Memtest.efi6.3.9600.180061,287,00006-Aug-201518:24Not applicable
Memtest.exe6.3.9600.180061,193,28806-Aug-201518:24x86
Winload.efi6.3.9600.180061,388,93606-Aug-201518:23Not applicable
Winload.exe6.3.9600.180061,277,88806-Aug-201518:23x86
Winresume.efi6.3.9600.180061,269,07206-Aug-201518:23Not applicable
Winresume.exe6.3.9600.180061,168,92006-Aug-201518:23x86
For all supported x64-based versions of Windows 8.1 or Windows Server 2012 R2
File nameFile versionFile sizeDateTimePlatform
Hvax64.exe6.3.9600.180061,381,70406-Aug-201519:16x64
Hvix64.exe6.3.9600.180061,424,71206-Aug-201519:16x64
Hvloader.efi6.3.9600.180061,392,96806-Aug-201519:16Not applicable
Hvloader.exe6.3.9600.180061,265,99206-Aug-201519:16x64
Hvservice.sys6.3.9600.1782668,95212-May-201500:24x64
Kdhvcom.dll6.3.9600.1782619,80012-May-201500:24x64
Winresume.efi6.3.9600.180061,487,00806-Aug-201519:15Not applicable
Winresume.exe6.3.9600.180061,355,84806-Aug-201519:15x64
Winload.efi6.3.9600.180061,658,54406-Aug-201519:15Not applicable
Winload.exe6.3.9600.180061,519,59206-Aug-201519:15x64
Wdsmgfw.efi6.3.9600.180061,471,81606-Aug-201520:37Not applicable
Bootmgfw.efi6.3.9600.180061,619,80006-Aug-201519:16Not applicable
Bootmgr.efi6.3.9600.180061,617,73606-Aug-201519:16Not applicable
Memtest.efi6.3.9600.180061,500,48806-Aug-201519:16Not applicable
Winload.efi6.3.9600.180061,658,54406-Aug-201519:15Not applicable
Winload.exe6.3.9600.180061,519,59206-Aug-201519:15x64
Winresume.efi6.3.9600.180061,487,00806-Aug-201519:15Not applicable
Winresume.exe6.3.9600.180061,355,84806-Aug-201519:15x64
Bootmgfw.efi6.3.9600.180061,619,80006-Aug-201519:16Not applicable
Wdsmgfw.efi6.3.9600.180061,471,81606-Aug-201520:37Not applicable
Memtest.exe6.3.9600.180061,193,28806-Aug-201518:24x86
Abortpxe.comNot applicable7918-Jun-201312:18Not applicable
Bootmgr.exe6.3.9600.18006657,73606-Aug-201518:24x86
Hdlscom1.comNot applicable25,66218-Jun-201312:18Not applicable
Hdlscom1.n12Not applicable25,64618-Jun-201312:18Not applicable
Hdlscom2.comNot applicable25,66218-Jun-201312:18Not applicable
Hdlscom2.n12Not applicable25,64618-Jun-201312:18Not applicable
Pxeboot.comNot applicable25,35818-Jun-201312:18Not applicable
Pxeboot.n12Not applicable25,35818-Jun-201312:18Not applicable
Wdsnbp.comNot applicable30,83218-Jun-201312:18Not applicable
Abortpxe.comNot applicable7918-Jun-201312:18Not applicable
Bootmgfw.efi6.3.9600.180061,357,12806-Aug-201518:24Not applicable
Bootmgr.exe6.3.9600.18006657,73606-Aug-201518:24x86
Hdlscom1.comNot applicable25,66218-Jun-201312:18Not applicable
Hdlscom1.n12Not applicable25,64618-Jun-201312:18Not applicable
Hdlscom2.comNot applicable25,66218-Jun-201312:18Not applicable
Hdlscom2.n12Not applicable25,64618-Jun-201312:18Not applicable
Pxeboot.comNot applicable25,35818-Jun-201312:18Not applicable
Pxeboot.n12Not applicable25,35818-Jun-201312:18Not applicable
Wdsnbp.comNot applicable30,83218-Jun-201312:18Not applicable
For all supported Windows RT 8.1
File nameFile versionFile sizeDateTimePlatform
Winload.efi6.3.9600.18006780,40806-Aug-201517:23Not applicable
Wdsmgfw.efi6.3.9600.18006659,81606-Aug-201517:34Not applicable
Bootmgfw.efi6.3.9600.18006770,38406-Aug-201517:25Not applicable
Bootmgr.efi6.3.9600.18006766,31206-Aug-201517:25Not applicable
Winload.efi6.3.9600.18006780,40806-Aug-201517:23Not applicable

Additional file information


Additional file information for Windows 8.1 and for Windows Server 2012 R2

Additional files for all supported x86-based versions of Windows 8.1
File propertyValue
File nameX86_2d9269bddeea896bc6747acd6360c4f9_31bf3856ad364e35_6.3.9600.18006_none_e75c54fae058bac6.manifest
File versionNot applicable
File size712
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameX86_510ee3d21c7511e4f84b6603257f44c3_31bf3856ad364e35_6.3.9600.18006_none_42cd5991d8a162c7.manifest
File versionNot applicable
File size718
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameX86_b6dd04b7652a24eb241caca0e9e048db_31bf3856ad364e35_6.3.9600.18006_none_c4dea897a0f019f2.manifest
File versionNot applicable
File size725
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameX86_d88e9048075b92f769a7393d6bf605b2_31bf3856ad364e35_6.3.9600.18006_none_c9addd1b59bc2263.manifest
File versionNot applicable
File size724
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameX86_e267487a8de0f0795f7e83fa3ec9b695_31bf3856ad364e35_6.3.9600.18006_none_9a6e3d9e2b3f1a98.manifest
File versionNot applicable
File size713
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameX86_f0c3a5c39856db79a1a233a1a0df42e7_31bf3856ad364e35_6.3.9600.18006_none_9e0e44d31b947eb4.manifest
File versionNot applicable
File size711
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameX86_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.3.9600.18006_none_fe30a863a821c24a.manifest
File versionNot applicable
File size4,291
Date (UTC)06-Aug-2015
Time (UTC)18:34
PlatformNot applicable
File nameX86_microsoft-windows-b..ment-windows-minwin_31bf3856ad364e35_6.3.9600.18006_none_e4e3b7941755b2c1.manifest
File versionNot applicable
File size2,996
Date (UTC)06-Aug-2015
Time (UTC)18:34
PlatformNot applicable
File nameX86_microsoft-windows-b..nvironment-pxe-base_31bf3856ad364e35_6.3.9600.18006_none_b38fa446999175b0.manifest
File versionNot applicable
File size2,962
Date (UTC)06-Aug-2015
Time (UTC)18:55
PlatformNot applicable
File nameX86_microsoft-windows-b..ore-bootmanager-efi_31bf3856ad364e35_6.3.9600.18006_none_1c78fa10b7b6ff49.manifest
File versionNot applicable
File size4,077
Date (UTC)06-Aug-2015
Time (UTC)18:34
PlatformNot applicable
File nameX86_microsoft-windows-b..re-memorydiagnostic_31bf3856ad364e35_6.3.9600.18006_none_6d2d5fa31ff47eef.manifest
File versionNot applicable
File size4,102
Date (UTC)06-Aug-2015
Time (UTC)18:34
PlatformNot applicable
File nameX86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.18006_none_f01ecb6b87fe0479.manifest
File versionNot applicable
File size5,804
Date (UTC)06-Aug-2015
Time (UTC)18:34
PlatformNot applicable

Additional files for all supported x64-based versions of Windows 8.1 and of Windows Server 2012 R2
File propertyValue
File nameAmd64_0e00e0e47a055c32af6249ff543ace5f_31bf3856ad364e35_6.3.9600.18006_none_6f68c9ee519c8f4f.manifest
File versionNot applicable
File size1,112
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameAmd64_28e3476b874c532fc4ef237249d12cd7_31bf3856ad364e35_6.3.9600.18006_none_52b6b7b01f7af755.manifest
File versionNot applicable
File size728
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameAmd64_3e1f38ac7be00da8b38af30fed1d0bb2_31bf3856ad364e35_6.3.9600.18006_none_ba874362bd717638.manifest
File versionNot applicable
File size716
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameAmd64_7eed661f949d7b2431e602db89b59ec6_31bf3856ad364e35_6.3.9600.18006_none_b7c84798e354f3bd.manifest
File versionNot applicable
File size729
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameAmd64_8130f5eed007faaf6cfb1b886e0dd864_31bf3856ad364e35_6.3.9600.18006_none_d4c6e560e565823f.manifest
File versionNot applicable
File size1,100
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameAmd64_869365663bd7b134374159ae996e42c2_31bf3856ad364e35_6.3.9600.18006_none_c62ccbb97a8bf80c.manifest
File versionNot applicable
File size717
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameAmd64_a8597e4771299a3a262f6da55b2a7247_31bf3856ad364e35_6.3.9600.18006_none_e5eaac7583cbccb1.manifest
File versionNot applicable
File size715
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameAmd64_b1af5a9e4c270c1552f0619ebae6c005_31bf3856ad364e35_6.3.9600.18006_none_a2b824bb17d4054b.manifest
File versionNot applicable
File size1,092
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameAmd64_c3e7c0c448982f3732e9628addc155f0_31bf3856ad364e35_6.3.9600.18006_none_2eef175bead91b21.manifest
File versionNot applicable
File size710
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameAmd64_c89cd1762e5916592ac9dad9a7b22095_31bf3856ad364e35_6.3.9600.18006_none_2d4b0a5f6998825a.manifest
File versionNot applicable
File size722
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameAmd64_eede01337c23fa6f8327121192eb79a5_31bf3856ad364e35_6.3.9600.18006_none_12a08d57934f2899.manifest
File versionNot applicable
File size729
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameAmd64_f54f2207996fb0f1f780dcea00d22651_31bf3856ad364e35_6.3.9600.18006_none_62c1c632f112942d.manifest
File versionNot applicable
File size734
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameAmd64_f5b1538b52c727568d2752d1f8df98bd_31bf3856ad364e35_6.3.9600.18006_none_7abbc28991cf41b7.manifest
File versionNot applicable
File size726
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameAmd64_microsoft-hyper-v-drivers-hypervisor_31bf3856ad364e35_6.3.9600.18006_none_2168001e3939dd1e.manifest
File versionNot applicable
File size6,493
Date (UTC)07-Aug-2015
Time (UTC)07:51
PlatformNot applicable
File nameAmd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.3.9600.18006_none_5a4f43e7607f3380.manifest
File versionNot applicable
File size4,297
Date (UTC)06-Aug-2015
Time (UTC)20:36
PlatformNot applicable
File nameAmd64_microsoft-windows-b..ment-windows-minwin_31bf3856ad364e35_6.3.9600.18006_none_41025317cfb323f7.manifest
File versionNot applicable
File size3,000
Date (UTC)06-Aug-2015
Time (UTC)20:36
PlatformNot applicable
File nameAmd64_microsoft-windows-b..nvironment-pxe-base_31bf3856ad364e35_6.3.9600.18006_none_0fae3fca51eee6e6.manifest
File versionNot applicable
File size2,966
Date (UTC)06-Aug-2015
Time (UTC)20:53
PlatformNot applicable
File nameAmd64_microsoft-windows-b..ore-bootmanager-efi_31bf3856ad364e35_6.3.9600.18006_none_789795947014707f.manifest
File versionNot applicable
File size4,083
Date (UTC)06-Aug-2015
Time (UTC)20:36
PlatformNot applicable
File nameAmd64_microsoft-windows-b..re-memorydiagnostic_31bf3856ad364e35_6.3.9600.18006_none_c94bfb26d851f025.manifest
File versionNot applicable
File size3,352
Date (UTC)06-Aug-2015
Time (UTC)20:36
PlatformNot applicable
File nameAmd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.18006_none_4c3d66ef405b75af.manifest
File versionNot applicable
File size5,810
Date (UTC)06-Aug-2015
Time (UTC)20:36
PlatformNot applicable
File nameAmd64_microsoft-windows-d..files-x64-minkernel_31bf3856ad364e35_6.3.9600.18006_none_fca26b131fedbb85.manifest
File versionNot applicable
File size3,746
Date (UTC)06-Aug-2015
Time (UTC)20:36
PlatformNot applicable
File nameAmd64_microsoft-windows-d..ices-boot-files-x64_31bf3856ad364e35_6.3.9600.18006_none_ad3e1ca591f98423.manifest
File versionNot applicable
File size3,690
Date (UTC)06-Aug-2015
Time (UTC)20:53
PlatformNot applicable
File nameAmd64_microsoft-windows-d..ices-boot-files-x86_31bf3856ad364e35_6.3.9600.18006_none_ad3fefa991f7ea13.manifest
File versionNot applicable
File size2,463
Date (UTC)06-Aug-2015
Time (UTC)20:52
PlatformNot applicable
File nameWow64_microsoft-windows-b..re-memorydiagnostic_31bf3856ad364e35_6.3.9600.18006_none_d3a0a5790cb2b220.manifest
File versionNot applicable
File size3,351
Date (UTC)06-Aug-2015
Time (UTC)18:33
PlatformNot applicable
File nameX86_microsoft-windows-d..files-x64-minkernel_31bf3856ad364e35_6.3.9600.18006_none_a083cf8f67904a4f.manifest
File versionNot applicable
File size9,946
Date (UTC)06-Aug-2015
Time (UTC)18:34
PlatformNot applicable
File nameX86_microsoft-windows-d..files-x86-minkernel_31bf3856ad364e35_6.3.9600.18006_none_98c45fc97adab83f.manifest
File versionNot applicable
File size10,723
Date (UTC)06-Aug-2015
Time (UTC)18:34
PlatformNot applicable
File nameX86_microsoft-windows-d..ices-boot-files-x64_31bf3856ad364e35_6.3.9600.18006_none_511f8121d99c12ed.manifest
File versionNot applicable
File size2,447
Date (UTC)06-Aug-2015
Time (UTC)18:54
PlatformNot applicable

Additional files for all supported Windows RT 8.1
File propertyValue
File nameArm_3216cdd574c02ae29176bcb152a40772_31bf3856ad364e35_6.3.9600.18006_none_000f613e74ad6a65.manifest
File versionNot applicable
File size718
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameArm_429874a760739a19345ceb116d565e07_31bf3856ad364e35_6.3.9600.18006_none_00046742517fc288.manifest
File versionNot applicable
File size713
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameArm_4542dd65040b23985f497828c43dde37_31bf3856ad364e35_6.3.9600.18006_none_a54b59e14ec50ea0.manifest
File versionNot applicable
File size724
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameArm_655cb0b7a0eaf88dda4d21aa3e93bf72_31bf3856ad364e35_6.3.9600.18006_none_0a20d08e7506d998.manifest
File versionNot applicable
File size712
Date (UTC)07-Aug-2015
Time (UTC)07:42
PlatformNot applicable
File nameArm_microsoft-windows-b..ment-windows-minwin_31bf3856ad364e35_6.3.9600.18006_none_e4e629ec1752d187.manifest
File versionNot applicable
File size2,228
Date (UTC)06-Aug-2015
Time (UTC)17:32
PlatformNot applicable
File nameArm_microsoft-windows-b..nvironment-pxe-base_31bf3856ad364e35_6.3.9600.18006_none_b392169e998e9476.manifest
File versionNot applicable
File size2,962
Date (UTC)06-Aug-2015
Time (UTC)17:44
PlatformNot applicable
File nameArm_microsoft-windows-b..ore-bootmanager-efi_31bf3856ad364e35_6.3.9600.18006_none_1c7b6c68b7b41e0f.manifest
File versionNot applicable
File size4,077
Date (UTC)06-Aug-2015
Time (UTC)17:32
PlatformNot applicable
File nameArm_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.3.9600.18006_none_f0213dc387fb233f.manifest
File versionNot applicable
File size3,539
Date (UTC)06-Aug-2015
Time (UTC)17:32
PlatformNot applicable


Status
Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.
References
See the terminology that Microsoft uses to describe software updates.
More information

Known issues about this update

Some Windows 8.1-based computers that installed the first version of this update may experience Secure Boot failures. Microsoft is aware of the issue and has re-released this update to fix this problem.

Affected devices that are known to Microsoft:
  • The Dell Venue line (Dell Venue 8, Dell Venue 10, Dell Venue 11 are known to be affected).
  • Other AMI BIOS-based systems, including the Linx 7 inch tablet.  

       
The firmware in these devices can't handle a larger code signing signature that was applied to the boot loader file bootmgfw.efi.

Symptoms

Devices experience boot failures after you install this update.The firmware on these devices produces an error message that looks something like:

Secure Boot Violation

Invalid signature detected. Check Secure Boot Policy in Setup. 

Workaround

To work around this problem, use the following methods:
  • Turn off Secure Boot temporarily, and enter the BitLocker recovery key during startup.
  • Install the re-release of this update.
  • Re-enable Secure Boot.
Third-party information disclaimer

The third-party products that this article discusses are manufactured by companies that are independent of Microsoft. Microsoft makes no warranty, implied or otherwise, about the performance or reliability of these products.

Свойства

ИД на статията: 3084905 – Последен преглед: 10/15/2015 02:36:00 – Редакция: 3.0

Windows Server 2012 R2 Datacenter, Windows Server 2012 R2 Standard, Windows Server 2012 R2 Essentials, Windows Server 2012 R2 Foundation, Windows 8.1 Enterprise, Windows 8.1 Pro, Windows 8.1, Windows RT 8.1

  • kbsurveynew atdownload kbexpertiseadvanced kbfix KB3084905
Обратна връзка