Microsoft security advisory: Improperly issued digital certificates ...
Provides a link to Microsoft Security Advisory: Incorrectly issued digital certificates could allow spoofing.
Microsoft security advisory: Inadvertently disclosed digital ...
Microsoft is aware of legitimate kernel drivers for D-Link products (including network adapters) that were signed by the affected D-Link certificates. These drivers include the Windows 7 drivers on the installation CD for the DUB-E100 USB network adapter.
Protections for CVE-2025-26647 (Kerberos Authentication)
In this article Summary Take Action altSecID attributes Timeline of changes Registry Settings Audit Events Event ID: 45 Event ID: 21 Known issue Summary The Windows security updates released on or after April 8, 2025, contain protections for a vulnerability with Kerberos authentication. This update provides a change in behavior when the issuing authority of the certificate used for a security ...
Guidance for certificate handling for Smart Card propagated ...
Introduction The October 14, 2025, Windows updates addressing CVE-2024-30098 revealed issues in applications where the code does not correctly identify which provider is managing the key for certificates propagated from a smart card to the certificate store. This misidentification can cause cryptographic operations to fail in certain scenarios.
Known issues and resolutions for Secure Boot certificates updates ...
This article provides the latest information and status for known issues in Windows or Microsoft Intune related to Secure Boot certificates. For problems deploying Secure Boot certificates that are not caused by known issues in Windows or Microsoft Intune, please refer to the Secure Boot troubleshooting guide.
Surface Secure Boot Certificates | Microsoft Support
Regardless of the method used to update Secure Boot certificates, all Surface devices in the table below (and those released in 2024 and later) have updated recovery images available from Microsoft that require these certificates.
Enterprise Deployment Guidance for CVE-2023-24932 | Microsoft Support
Introduction This document describes the deployment of the protections against the publicly disclosed Secure Boot security feature bypass that uses the BlackLotus UEFI bootkit tracked by CVE-2023-24932 for enterprise environments. To avoid disruptions, Microsoft does not plan to deploy these mitigations in enterprises but is providing this guidance to help enterprises apply the mitigations ...
Description of the security update for SharePoint Server 2016: January ...
This security update resolves Microsoft Office Click-To-Run Elevation of Privilege vulnerability, Microsoft SharePoint Remote Code Execution vulnerability, Microsoft SharePoint Information Disclosure vulnerability, Microsoft Word Remote Code Execution vulnerability, Microsoft SharePoint Server Remote Code Execution vulnerability, and Microsoft SharePoint Server Spoofing vulnerability. To learn ...
Latest Windows hardening guidance and key dates
Introduction Hardening is a key element of our ongoing security strategy to help keep your estate protected while you focus on your job. Increasingly creative cyberthreats target weaknesses anywhere possible, from the chip to the cloud. This article reviews vulnerable areas that are undergoing hardening changes implemented via Windows security updates. We also post reminders on Windows message ...
If you’re prevented from updating Secure Boot certificates
Introduction Microsoft is rolling out updated Secure Boot certificates to Windows devices to maintain protection against evolving boot-level threats. Most devices receive these updates automatically through Windows Update. This article explains why some devices are blocked from updating Secure Boot certificates, what this means, and what actions you can consider.