MS16-094: Description of the security update for Secure Boot: July 12, 2016

Summary

This security update resolves a vulnerability in Microsoft Windows that could allow Secure Boot security features to be bypassed if an attacker installs an affected policy on a target device. An attacker must have either administrative privileges or physical access to install a policy and bypass Secure Boot.


To learn more about the vulnerability, see Microsoft Security Bulletin MS16-094.

More Information

Important

  • All future security and non-security updates for Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2 require update 2919355 to be installed. We recommend that you install update 2919355 on your Windows RT 8.1-based, Windows 8.1-based, or Windows Server 2012 R2-based computer so that you receive future updates.

  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.

How to obtain and install the update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see
Get security updates automatically.

Note For Windows RT 8.1, this update is available through Windows Update only.

You can obtain the stand-alone update package through the Microsoft Download Center. Follow the installation instructions on the download page to install the update.

Click the download link in Microsoft Security Bulletin MS16-094 that corresponds to the version of Windows that you are running.

More Information

Help for installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help for protecting your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

File Information

File name

Package hash SHA1

Package hash SHA2

Windows8.1-KB3172727-x86.msu

9B3A9404F262B22ADA0434E5432CDDDCCA344E91

BFC8B9D4B8298D691931E4EA2C876D0B394DFDE0A781CC4EAE2392A44318C747

Windows8.1-KB3172727-x64.msu

881DFB1EE768A4DFCAAA6DFE67A9A59072577349

BC424D3016EB7DE18D9F96717BBCB91F260E64938AAB5D36893CEC15268C0031

Windows8-RT-KB3172727-x64.msu

B2BBDE1BCBCAE514A5149618B8AA401A3022FBB3

6AA77FE04F7EC823AB0EB16079E06936FFB713FCB0C2205F4C5287BDEC1BC1AD


The English (United States) version of this software update installs files that have the attributes that are listed in the following tables.

Windows 8.1 and Windows Server 2012 R2 file information

Notes

  • The files that apply to a specific product, milestone (RTM, SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table:

    Version

    Product

    Milestone

    Service branch

    6.3.960 0.16xxx

    Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2

    RTM

    GDR

    6.3.960 0.17xxx

    Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2

    RTM

    GDR

    6.3.960 0.18xxx

    Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2

    RTM

    GDR

  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.

  • The MANIFEST files (.manifest) and MUM files (.mum) that are installed are not listed.

For all supported x86-based versions

File name

File version

File size

Date

Time

Platform

Boot.stl

Not applicable

4,669

24-Jun-2016

13:35

Not applicable

Ci.dll

6.3.9600.17550

485,544

08-Dec-2014

19:46

x86

Driver.stl

Not applicable

4,538

24-Jun-2016

13:35

Not applicable

For all supported x64-based versions

File name

File version

File size

Date

Time

Platform

Boot.stl

Not applicable

4,669

24-Jun-2016

13:46

Not applicable

Ci.dll

6.3.9600.17550

531,616

08-Dec-2014

19:42

x64

Driver.stl

Not applicable

4,652

24-Jun-2016

13:46

Not applicable

Windows Server 2012 file information

Notes

  • The files that apply to a specific product, milestone (RTM, SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table:

    Version

    Product

    Milestone

    Service branch

    6.2.920 0.17xxx

    Windows 8, Windows RT, or Windows Server 2012

    RTM

    GDR

    6.2.920 0.21xxx

    Windows 8, Windows RT, or Windows Server 2012

    RTM

    LDR

  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.

  • The MANIFEST files (.manifest) and MUM files (.mum) that are installed are not listed.

For all supported x64-based versions

File name

File version

File size

Date

Time

Platform

SP requirement

Service branch

Winload.efi

6.2.9200.21638

1,405,408

22-Sep-2015

21:46

Not applicable

None

Not applicable

Winload.exe

6.2.9200.21638

1,273,184

22-Sep-2015

21:46

x64

None

Not applicable

Winresume.efi

6.2.9200.20726

1,217,352

25-May-2013

00:17

Not applicable

None

Not applicable

Winresume.exe

6.2.9200.20726

1,093,904

25-May-2013

00:17

x64

None

Not applicable

Boot.stl

Not applicable

4,629

24-Jun-2016

13:10

Not applicable

None

Not applicable

Ci.dll

6.2.9200.20679

503,080

04-Apr-2013

22:04

x64

None

Not applicable

Driver.stl

Not applicable

4,367

24-Jun-2016

13:10

Not applicable

None

Not applicable

Ksecdd.sys

6.2.9200.21473

100,184

02-May-2015

06:23

x64

None

Not applicable

Lsass.exe

6.2.9200.20521

35,840

20-Sep-2012

06:33

x64

None

Not applicable

Sspicli.dll

6.2.9200.21703

164,352

17-Nov-2015

08:00

x64

None

Not applicable

Sspisrv.dll

6.2.9200.20521

27,648

20-Sep-2012

06:32

x64

None

Not applicable

Cng.sys

6.2.9200.21637

566,072

22-Sep-2015

13:43

x64

None

Not applicable

Ksecpkg.sys

6.2.9200.21858

171,360

10-May-2016

19:18

x64

None

Not applicable

Lsasrv.dll

6.2.9200.21830

1,280,000

09-Apr-2016

16:01

x64

None

Not applicable

Adtschema.dll

6.2.9200.21289

719,360

10-Nov-2014

04:43

x64

None

Not applicable

Msaudite.dll

6.2.9200.21269

146,944

11-Oct-2014

05:38

x64

None

Not applicable

Msobjs.dll

6.2.9200.16384

61,952

26-Jul-2012

02:36

x64

None

Not applicable

Ocspsvcctrs.ini

Not applicable

2,960

26-Jul-2012

05:07

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

3,134

26-Jul-2012

08:00

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

2,918

26-Jul-2012

04:43

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

3,210

26-Jul-2012

07:59

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

3,098

26-Jul-2012

08:00

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

3,028

26-Jul-2012

07:59

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

3,140

26-Jul-2012

05:21

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

2,642

26-Jul-2012

08:11

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

2,576

26-Jul-2012

05:20

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

3,026

26-Jul-2012

07:36

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

3,028

26-Jul-2012

07:48

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

3,188

26-Jul-2012

05:30

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

3,126

26-Jul-2012

05:08

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

3,064

26-Jul-2012

07:49

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

3,092

26-Jul-2012

07:52

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

2,828

26-Jul-2012

05:12

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

2,464

26-Jul-2012

08:05

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

2,480

26-Jul-2012

05:13

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

2,460

26-Jul-2012

08:11

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvc.exe

6.2.9200.21345

272,384

15-Jan-2015

05:27

x64

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.h

Not applicable

1,569

02-Jun-2012

14:34

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ocspsvcctrs.ini

Not applicable

2,918

02-Jun-2012

14:34

Not applicable

SPS

AMD64_MICROSOFT-WINDOWS-OCSP

Ntoskrnl.exe

6.2.9200.21914

6,937,952

01-Jul-2016

16:27

x64

None

Not applicable

Credssp.dll

6.2.9200.21703

20,480

17-Nov-2015

07:59

x64

SP_

AMD64_MICROSOFT-WINDOWS-SECURITY-CREDSSP

Tspkg.dll

6.2.9200.21703

94,720

17-Nov-2015

08:01

x64

SP_

AMD64_MICROSOFT-WINDOWS-SECURITY-CREDSSP

Tspkg.mof

Not applicable

964

02-Jun-2012

14:33

Not applicable

SP_

AMD64_MICROSOFT-WINDOWS-SECURITY-CREDSSP

Wdigest.dll

6.2.9200.21858

208,896

10-May-2016

17:07

x64

None

Not applicable

Kerberos.dll

6.2.9200.21830

829,952

09-Apr-2016

16:01

x64

None

Not applicable

Msv1_0.dll

6.2.9200.21830

317,952

09-Apr-2016

16:01

x64

None

Not applicable

Shcore.dll

6.2.9200.21703

590,848

17-Nov-2015

08:00

x64

None

Not applicable

Mrxsmb10.sys

6.2.9200.21529

281,600

25-Jun-2015

18:52

x64

None

Not applicable

Mrxsmb20.sys

6.2.9200.21548

205,312

11-Jul-2015

17:07

x64

None

Not applicable

Mrxsmb.sys

6.2.9200.21342

396,800

06-Jan-2015

23:17

x64

None

Not applicable

Lsm.dll

6.2.9200.21703

439,808

17-Nov-2015

08:00

x64

None

Not applicable

Workerdd.dll

6.2.9200.21012

14,848

12-Apr-2014

06:58

x64

None

Not applicable

Usercpl.dll

6.2.9200.21703

1,043,968

17-Nov-2015

08:01

x64

None

Not applicable

Usercpl.ptxml

Not applicable

789

11-Oct-2012

00:40

Not applicable

None

Not applicable

Winlogon.exe

6.2.9200.21703

578,048

17-Nov-2015

08:01

x64

None

Not applicable

Sspicli.dll

6.2.9200.20984

99,840

10-Mar-2014

01:34

x86

None

Not applicable

Wdigest.dll

6.2.9200.21858

176,640

10-May-2016

17:55

x86

None

Not applicable

Kerberos.dll

6.2.9200.21830

666,112

09-Apr-2016

16:48

x86

None

Not applicable

Msv1_0.dll

6.2.9200.21830

274,944

09-Apr-2016

16:48

x86

None

Not applicable

Adtschema.dll

6.2.9200.21289

719,360

10-Nov-2014

03:40

x86

None

Not applicable

Msaudite.dll

6.2.9200.21269

146,944

11-Oct-2014

04:35

x86

None

Not applicable

Msobjs.dll

6.2.9200.16384

61,952

26-Jul-2012

02:47

x86

None

Not applicable

Credssp.dll

6.2.9200.21703

17,408

17-Nov-2015

08:08

x86

SP_

X86_MICROSOFT-WINDOWS-SECURITY-CREDSSP

Tspkg.dll

6.2.9200.21703

76,800

17-Nov-2015

08:09

x86

SP_

X86_MICROSOFT-WINDOWS-SECURITY-CREDSSP

Tspkg.mof

Not applicable

964

02-Jun-2012

14:33

Not applicable

SP_

X86_MICROSOFT-WINDOWS-SECURITY-CREDSSP

Shcore.dll

6.2.9200.21703

460,800

17-Nov-2015

08:09

x86

None

Not applicable

Usercpl.dll

6.2.9200.21703

961,536

17-Nov-2015

08:09

x86

None

Not applicable

Usercpl.ptxml

Not applicable

789

11-Oct-2012

00:42

Not applicable

None

Not applicable


Need more help?

Expand your skills
Explore Training
Get new features first
Join Microsoft Insiders

Was this information helpful?

Thank you for your feedback!

Thank you for your feedback! It sounds like it might be helpful to connect you to one of our Office support agents.

×