Hello Broadway, Scott (Entrust),
The CRITICAL_SERVICE_FAILED error immediately after installing KB5120238 on Windows Server 2019 guest systems indicates a bootloader path conflict triggered by the new signature check in the update. Since your diagnostics have already confirmed that the UEFI certificate database is correct and the host infrastructure is up to date, this is not a firmware mismatch, but rather a regression issue within the patch itself. In similar cases, Microsoft has recommended temporarily reverting the affected VM to its last working state and blocking the update until a corrected build is released.
... A technical workaround is to uninstall the update offline using dism /image:C:\ /remove-package /packageName:Package_for_KB5120238~31bf3856ad364e35~amd64~~<version> and then specifically exclude the patch via WSUS or Windows Update. A permanent solution can only be achieved through a subsequent servicing release from Microsoft, as the signature verification in the kernel cannot be manually overridden. If you absolutely must keep the environment up to date, it is recommended to maintain a test system with an identical configuration and validate the next cumulative updates there before deploying them to the production environment.
If my answer is helpful to you, please click "Accept the answer" to support me.
Thank you,
HL.