Categories: SecurityWindows 10

Microsoft Windows 10 security updates KB4532695 and KB4528760 causes TPM driver to fail and results in windows 10 BSOD

&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2522 " id&equals;"quads-ad2522" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine;<h2>Update&colon; For the solution scroll to the end of the page&period;<&sol;h2>&NewLine;<h2>Windows 10 Update &colon;<&sol;h2>&NewLine;<p>Yesterday and today Microsoft released KB4532695 and KB4528760 causes TPM 2&period;0 driver to stop functioning and causes BSOD with error &&num;8220&semi;<b>Memory Management<&sol;b>&&num;8221&semi; Issue&period;<&sol;p>&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2524 " id&equals;"quads-ad2524" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine;&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2530 " id&equals;"quads-ad2530" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine;&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2531 " id&equals;"quads-ad2531" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine;&NewLine;<p><a href&equals;"https&colon;&sol;&sol;www&period;moh10ly&period;com&sol;wp-content&sol;uploads&sol;2020&sol;01&sol;clip&lowbar;image001-3&period;png"><img style&equals;"margin&colon; 0px&semi; display&colon; inline&semi; background-image&colon; none&semi;" title&equals;"clip&lowbar;image001" src&equals;"https&colon;&sol;&sol;www&period;moh10ly&period;com&sol;wp-content&sol;uploads&sol;2020&sol;01&sol;clip&lowbar;image001&lowbar;thumb-3&period;png" alt&equals;"clip&lowbar;image001" width&equals;"681" height&equals;"312" border&equals;"0" &sol;><&sol;a> &NewLine;&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2528 " id&equals;"quads-ad2528" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine; &NewLine;<&sol;p>&NewLine;<p><a href&equals;"https&colon;&sol;&sol;www&period;moh10ly&period;com&sol;wp-content&sol;uploads&sol;2020&sol;01&sol;image-60&period;png"><img style&equals;"margin&colon; 0px&semi; display&colon; inline&semi; background-image&colon; none&semi;" title&equals;"image" src&equals;"https&colon;&sol;&sol;www&period;moh10ly&period;com&sol;wp-content&sol;uploads&sol;2020&sol;01&sol;image&lowbar;thumb-60&period;png" alt&equals;"image" width&equals;"642" height&equals;"484" border&equals;"0" &sol;><&sol;a><&sol;p>&NewLine;<h2>Windows Hello Face Authentication<&sol;h2>&NewLine;<p>In the first KB Microsoft says they have improved the accuracy of Windows Hello Face authentication however this would cause your PIN to be reset&comma; TPM driver stop functioning and BitLocker to change in Pause state&period;<&sol;p>&NewLine;<p><a href&equals;"https&colon;&sol;&sol;support&period;microsoft&period;com&sol;en-us&sol;help&sol;4532695&sol;windows-10-update-kb4532695" target&equals;"&lowbar;blank" rel&equals;"noopener noreferrer"><span style&equals;"color&colon; &num;0000ff&semi;">Check KB Article here<&sol;span><&sol;a><&sol;p>&NewLine;<p><a href&equals;"https&colon;&sol;&sol;www&period;moh10ly&period;com&sol;wp-content&sol;uploads&sol;2020&sol;01&sol;clip&lowbar;image0014-2&period;png"><img style&equals;"margin&colon; 0px&semi; display&colon; inline&semi; background-image&colon; none&semi;" title&equals;"clip&lowbar;image001&lbrack;4&rsqb;" src&equals;"https&colon;&sol;&sol;www&period;moh10ly&period;com&sol;wp-content&sol;uploads&sol;2020&sol;01&sol;clip&lowbar;image0014&lowbar;thumb-2&period;png" alt&equals;"clip&lowbar;image001&lbrack;4&rsqb;" width&equals;"384" height&equals;"560" border&equals;"0" &sol;><&sol;a><&sol;p>&NewLine;<p><a href&equals;"https&colon;&sol;&sol;www&period;moh10ly&period;com&sol;wp-content&sol;uploads&sol;2020&sol;01&sol;image-61&period;png"><img style&equals;"margin&colon; 0px&semi; display&colon; inline&semi; background-image&colon; none&semi;" title&equals;"image" src&equals;"https&colon;&sol;&sol;www&period;moh10ly&period;com&sol;wp-content&sol;uploads&sol;2020&sol;01&sol;image&lowbar;thumb-61&period;png" alt&equals;"image" width&equals;"1028" height&equals;"453" border&equals;"0" &sol;><&sol;a><&sol;p>&NewLine;<p>The BSOD will generate an event ID 1001 stating the bugcheck code and saves a dump&period; &lpar; I haven&&num;8217&semi;t analyzed that yet&rpar;&period;<&sol;p>&NewLine;<p><a href&equals;"https&colon;&sol;&sol;www&period;moh10ly&period;com&sol;wp-content&sol;uploads&sol;2020&sol;01&sol;clip&lowbar;image0016-1&period;png"><img style&equals;"margin&colon; 0px&semi; display&colon; inline&semi; background-image&colon; none&semi;" title&equals;"clip&lowbar;image001&lbrack;6&rsqb;" src&equals;"https&colon;&sol;&sol;www&period;moh10ly&period;com&sol;wp-content&sol;uploads&sol;2020&sol;01&sol;clip&lowbar;image0016&lowbar;thumb-1&period;png" alt&equals;"clip&lowbar;image001&lbrack;6&rsqb;" width&equals;"1028" height&equals;"353" border&equals;"0" &sol;><&sol;a><&sol;p>&NewLine;<p>After Uninstalling the updates it was a no go but at least the Memory Management BSOD stopped&period;&period;<&sol;p>&NewLine;<p>Interesting thing is that not just TPM stopped&comma; now even Virtual Box says no Virtualization Capabilities supported on my Device which I had over 20 VMs on it and was working fine also before these updates&period;<&sol;p>&NewLine;<p>The TPM is indeed firmware as it&&num;8217&semi;s fixed on the board&period;&period;<&sol;p>&NewLine;<p>In the event viewer related to Device Manager &lpar;Trusted Platform Module 2&period;0&rpar; I see couple of errors sourced from Kernel-PnP and UserPnp<&sol;p>&NewLine;<p><strong>KernelPnp error<&sol;strong><&sol;p>&NewLine;<p><strong>Device ACPI&bsol;MSFT0101&bsol;1 had a problem starting&period;<&sol;strong><&sol;p>&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2525 " id&equals;"quads-ad2525" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine;&NewLine;<p>Driver Name&colon; tpm&period;inf<br &sol;>&NewLine;Class Guid&colon; &lbrace;d94ee5d8-d189-4994-83d2-f68d7d41b0e6&rcub;<br &sol;>&NewLine;Service&colon; TPM<br &sol;>&NewLine;Lower Filters&colon;<br &sol;>&NewLine;Upper Filters&colon;<br &sol;>&NewLine;Problem&colon; 0xA<br &sol;>&NewLine;Problem Status&colon; 0xC0000001<&sol;p>&NewLine;<p>&&num;8212&semi;-<&sol;p>&NewLine;<p><strong>Device ACPI&bsol;MSFT0101&bsol;1 was configured&period;<&sol;strong><&sol;p>&NewLine;<p>Driver Name&colon; tpm&period;inf<br &sol;>&NewLine;Class Guid&colon; &lbrace;d94ee5d8-d189-4994-83d2-f68d7d41b0e6&rcub;<br &sol;>&NewLine;Driver Date&colon; 06&sol;21&sol;2006<br &sol;>&NewLine;Driver Version&colon; 10&period;0&period;18362&period;267<br &sol;>&NewLine;Driver Provider&colon; Microsoft<br &sol;>&NewLine;Driver Section&colon; Tpm2BaseInstall<br &sol;>&NewLine;Driver Rank&colon; 0xFF0002<br &sol;>&NewLine;Matching Device Id&colon; &ast;MSFT0101<br &sol;>&NewLine;Outranked Drivers&colon; tpm&period;inf&colon;ACPI&bsol;MSFT0101&colon;00FF0001<br &sol;>&NewLine;Device Updated&colon; true<br &sol;>&NewLine;Parent Device&colon; ACPI&lowbar;HAL&bsol;PNP0C08&bsol;0<&sol;p>&NewLine;<p>&&num;8212&semi;-<&sol;p>&NewLine;<p><strong>UserPnp &lpar;Informational event&rpar; happens after Kernel-Pnp fail<&sol;strong><&sol;p>&NewLine;<p>Driver Management concluded the process to install driver tpm&period;inf&lowbar;amd64&lowbar;aaaa339206cb706e for Device Instance ID ACPI&bsol;MSFT0101&bsol;1 with the following status&colon; 0x0&period;<&sol;p>&NewLine;<h2>Solution&colon;<&sol;h2>&NewLine;<p>After two days of struggling I managed to find the solution&period;<&sol;p>&NewLine;<p>Disable Device Guard from Group Policy and PowerShell&period;<&sol;p>&NewLine;<ul>&NewLine;<li>To disable from PowerShell you&&num;8217&semi;ll need to download the Device Guard and Credential Guard hardware readiness tool which contains a script that would disable&sol;enable Device Guard&period;<&sol;li>&NewLine;<li>Use the following cmdlet &period;&bsol;DG&lowbar;Readiness&lowbar;Tool&lowbar;v3&period;6&period;ps1 -Disable after extracting the the DG readiness tools from the link below<&sol;li>&NewLine;<&sol;ul>&NewLine;<p>https&colon;&sol;&sol;www&period;microsoft&period;com&sol;en-us&sol;download&sol;details&period;aspx&quest;id&equals;53337<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-1788" src&equals;"https&colon;&sol;&sol;www&period;moh10ly&period;com&sol;wp-content&sol;uploads&sol;2020&sol;01&sol;disable&lowbar;deviceguard&lowbar;powershell&period;jpg" alt&equals;"" width&equals;"849" height&equals;"392" &sol;><&sol;p>&NewLine;<ul>&NewLine;<li>From Run type gpedit&period;msc and launch Group Policy then navigate to Computer Configuration &gt&semi; Administrative Templates &gt&semi; System &gt&semi; Device Guard and set &&num;8220&semi;Turn On Virtualization Based Security&&num;8221&semi; To Not Configured&period;<&sol;li>&NewLine;<&sol;ul>&NewLine;<p><img class&equals;"alignnone size-large wp-image-1787" src&equals;"https&colon;&sol;&sol;www&period;moh10ly&period;com&sol;wp-content&sol;uploads&sol;2020&sol;01&sol;GPO-1024x297&period;jpg" alt&equals;"" width&equals;"474" height&equals;"137" &sol;><&sol;p>&NewLine;<p>Once this is done&comma; Restart your Computer and Press F3 to disable Device Gaurd twice&period; When restarting the Computer will restart again and you&&num;8217&semi;ll see that your TPM is back to normal&period;<&sol;p>&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2527 " id&equals;"quads-ad2527" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine;&NewLine;<p><img class&equals;"alignnone size-full wp-image-1789" src&equals;"https&colon;&sol;&sol;www&period;moh10ly&period;com&sol;wp-content&sol;uploads&sol;2020&sol;01&sol;TPM&period;jpg" alt&equals;"" width&equals;"530" height&equals;"567" &sol;><&sol;p>&NewLine;&NewLine;<&excl;-- WP QUADS Content Ad Plugin v&period; 2&period;0&period;92 -->&NewLine;<div class&equals;"quads-location quads-ad2526 " id&equals;"quads-ad2526" style&equals;"float&colon;none&semi;margin&colon;0px 3px 3px 3px&semi;padding&colon;0px 0px 0px 0px&semi;" data-lazydelay&equals;"0">&NewLine;&NewLine;<&sol;div>&NewLine;&NewLine;

moh10ly

Recent Posts

Reset passwords for Active Directory Users

Reset and manage your Active Directory users' Passwords Active Directory is one of the most…

3 years ago

Finding Exchange Database hidden mailboxes. ​

Finding Exchange Database hidden mailboxes. Story:Maybe you have been in this situation before, trying to…

3 years ago

Setting up ADConnect and PTA (Password auth through) servers agents behind proxy

If you're using a Proxy server in your firewall or in your network and have…

3 years ago

Get Report of Active Directory Locked Accounts and Machine they logged in from

Story:I got some clients  that have reported some of their users being locked out and…

3 years ago

Checking and Providing Full and SendAs delegate access on O365 Exchange Online

Delegate Permissions This is a code that I have wrote recently to check if an…

3 years ago

Retrieving attachments from Exchange mailbox using python

Story: I got a request from a client who constantly gets CVs and have to…

4 years ago

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298

Warning: Undefined array key "adsense_ad_type" in /www/wwwroot/www.moh10ly.com/wp-content/plugins/quick-adsense-reloaded/includes/amp-condition-display.php on line 298