--- title: "Secure-Boot-Update in Windows causes system freezes" description: "Windows 10 and Windows 11 users report freezes caused by the Secure-Boot-Update task. Microsoft recommends checking UEFI firmware but not disabling the task." tags: [Windows, Secure-Boot-Update, freezes, UEFI] ### ⚡ The gist in 5 seconds - The mandatory scheduled task Secure-Boot-Update is causing Windows 10 and Windows 11 to freeze a few minutes after boot. - The issue occurs on both versions of the OS; in some cases, freezes only appear when connected to the internet. - There is no official fix yet — Microsoft advises checking UEFI firmware and not disabling the task unnecessarily. ### 🔍 What was found On September 27, 2026, Windows 10 and Windows 11 users reported computer freezes occurring a few minutes after the system boots. In some cases, the problem only appeared when connected to the internet, so it was initially attributed to networking. The culprit turned out to be the scheduled task Secure-Boot-Update, which is responsible for updating Secure Boot certificates. It runs automatically roughly every 12 hours and checks for operations that have not yet been completed. If the update encounters an error, Windows saves information about the incomplete operation and attempts to run it again. You can check the task's status via PowerShell with administrator rights: schtasks.exe /Query /TN "\Microsoft\Windows\PI\Secure-Boot-Update" /FO LIST /V. The "Status" field should normally read "Ready". If the freezes disappear after disabling this task, the problem lies specifically in the update execution. In that case, it is recommended to check for fresh UEFI firmware on your computer manufacturer's website. ### 💡 Why it matters Secure-Boot-Update is used to install new Secure Boot certificates, which protect the system from malicious bootkits and rootkits. That's why Microsoft recommends not disabling the task unnecessarily. Fully disabling it works only as a temporary workaround: it blocks further certificate updates and reduces the level of security. Instead, it's worth addressing the root cause — most often outdated UEFI firmware, especially on older machines. ### 🧩 Context Microsoft warns that failures are possible due to UEFI firmware issues or a lack of support for required features on the device. Updating the Secure Boot database and exchanging KEK keys may in some cases end in an error. Older computers whose manufacturers have long stopped releasing firmware updates are especially vulnerable. It is not yet known when an official fix will be released, so users are left either waiting or temporarily disabling the Secure-Boot-Update task.
Source: trashbox.ru · post in Telegram