KB5022842Catastrophic

Secure Boot update bricks VMware VMs and bare metal servers

What broke

February’s update shipped a new EFI bootloader signature that VMware ESXi 6.7 and 7.0 hosts rejected at the UEFI Secure Boot level. Windows Server 2022 VMs simply would not boot — they couldn’t find a bootable OS. Bare metal servers were also affected. The truly elegant part: uninstalling the KB didn’t fix it, because the new bootloader signature was already written. The only options were disabling Secure Boot entirely or upgrading ESXi. VMware had to rush out an emergency ESXi update. Microsoft had managed to brick VMs that couldn’t be un-bricked by removing the update.

Sources

  1. BleepingComputer: KB5022842 incident report
  2. Born's Tech and Windows World: KB5022842 incident report

Related Windows update incidents