Secure boot violation after installing a few updates

Liam Woodley 0 Reputation points
2026-09-18T14:36:57.4166667+00:00

Hello, I am currently dealing with an issue of a secure boot violation after installing a few updates today, I will list every update I've installed today now, if anyone knows what might be the problem that would be amazing if you could help me out!

Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.459.267.0) - Current Channel (Broad)
Intel - Other hardware - Intel(R) Xeon(R) E3 - 1200/1500 v5/6th Gen Intel(R) Core(TM) PCIe Controller (x16) - 1901
Intel - System - 9/19/2017 12:00:00 AM - 11.7.0.1000
Intel - net - 21.60.0.5
Micro-Star International Co., Ltd. - Firmware - 1.0.0.12
2026-09 .NET Framework Security Update (KB5126052)
2026-09 Security Update (KB5129195) (26200.9457)

Windows for home | Windows 11 | Performance and system failures
0 comments No comments

2 answers

Sort by: Oldest
  1. AI answer

    2026-09-18T14:37:18.9433333+00:00

    A Secure Boot violation immediately after updates is most consistent with a firmware or Secure Boot trust issue, not with the Defender, .NET, or Intel driver updates listed.

    The most relevant update in the list is:

    • Micro-Star International Co., Ltd. - Firmware - 1.0.0.12

    The documented failure patterns are:

    1. Device fails to boot after a firmware change or Secure Boot state change.
    2. A firmware or Secure Boot error appears before Windows loads.
    3. Disabling Secure Boot may allow Windows to start.

    Two supported paths are documented.

    1. If the problem started after Secure Boot settings were reset to firmware defaults
      • Resetting Secure Boot defaults can clear the firmware certificate databases.
      • On systems already using the newer Windows UEFI CA 2023 trust, that can remove the certificate needed to trust the installed Windows boot manager.
      • Recovery method:
        1. On a second Windows PC with the July 2024 or newer Windows update installed, copy SecureBootRecovery.efi from C:\Windows\Boot\EFI\.
        2. Put it on a FAT32 USB drive under \EFI\BOOT\.
        3. Rename it to bootx64.efi.
        4. Boot the affected PC from that USB drive and let the recovery utility run.
      • After recovery, install the latest firmware from the device manufacturer.
    2. If the problem started immediately after the firmware/update restart
      • Some UEFI firmware incorrectly overwrites the Secure Boot allowed signature database instead of appending to it.
      • Documented next steps:
        1. Enter firmware/BIOS setup.
        2. Attempt to reset Secure Boot settings.
        3. If the PC boots after that, check the device manufacturer support site for a firmware update that corrects Secure Boot DB handling.
        4. Install that firmware update before re-enabling Secure Boot and reapplying Secure Boot certificate updates.
      • If resetting Secure Boot does not restore boot functionality, further recovery likely requires OEM-specific guidance.

    Important risk note:

    • Resetting Secure Boot to firmware defaults can itself cause boot failure on some devices by clearing required trust certificates.
    • If Windows currently boots only with Secure Boot disabled, avoid repeated Secure Boot resets unless following the documented recovery path.

    Based on the update list alone, the MSI firmware update is the strongest suspect. The practical next step is:

    1. Test whether the system boots with Secure Boot disabled.
    2. In BIOS/UEFI, try a Secure Boot reset only once as a recovery step.
    3. If that does not fix it, use the Secure Boot recovery utility from USB.
    4. Then install the newest MSI firmware that addresses Secure Boot behavior.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

  2. DaveM121 934.5K Reputation points Independent Advisor
    2026-09-18T15:13:20.94+00:00

    The 'Micro-Star International Co., Ltd. - Firmware - 1.0.0.12' is the most likely cause of the Secure Boot Violation error, that is a BIOS update, did that update delivered by Windows updates?

    Before proceeding, please backup your files to avoid data loss.

    Boot your PC into BIOS and in the Security settings section, try resetting TPM to Factory keys to test if that resolves the problem.

    If that does not resolve the problem, go to the support page for your PC or motherboard to check if there is a BIOS update available that may not be installed yet.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.