📡 Breaking news
0/0
Analyzing latest trends...
AI Text-to-Speech.

Windows 10 and 11 System Freezes Tracked to Background Secure-Boot-Update Task.

Windows 10 and 11 System Freezes Tracked to Background Secure-Boot-Update Task.
Windows 10 and Windows 11 Users Report PC Freezes Caused by Background "Secure-Boot-Update" Task Amid 2026 Certificate Expirations

Reports have surfaced across online tech support communities from Windows 10 and Windows 11 users experiencing severe system responsiveness issues shortly after booting up. Affected users report that approximately 3 to 5 minutes post-boot, the operating system suffers a complete hard freeze or unresponsiveness, often preventing any interaction with the desktop environment or taskbar.

Investigations into system background processes reveal that the freezing corresponds directly to the execution interval of a built-in background scheduled task named Secure-Boot-Update. Temporary mitigations indicate that disabling this specific task restores normal operating performance, linking the issue to Microsoft's broader transition to updated UEFI security certificates across legacy hardware.

Root Cause Mechanics, Certificate Expiration Timeline, and System Behavior

  • The Expiration of Legacy 2011 Secure Boot Certificates:

    • 15-Year Certificate Lifespan: The original root certificate authorities and Key Exchange Keys issued by Microsoft for UEFI Secure Boot in 2011 are reaching their hard expiration limits throughout 2026.

    • Key Expiration Dates: The Microsoft Corporation KEK CA 2011 expired on June 24, 2026, the Microsoft Corporation UEFI CA 2011 expired on June 27, 2026, and the Microsoft Windows Production PCA 2011 certificate expires on October 19, 2026.

    • Modernization Deployment: To prevent bootloader vulnerabilities and maintain system integrity, Microsoft is deploying updated 2023-era certificates to the Secure Boot Allowed Signature Database on devices worldwide via cumulative Windows Updates.

  • Background Task Loops and Firmware Incompatibilities:

    • Background Execution: The process is governed by a native Windows scheduled task located within the Task Scheduler library under the Windows PI directory as Secure-Boot-Update.

    • The Incompatibility Loop: When the task triggers 3 to 5 minutes after boot, it attempts to write updated certificate signatures directly to the motherboard's Non-Volatile RAM via the system BIOS or UEFI layer.

    • System Lockup: On older hardware architectures or machines running outdated BIOS firmware, the system fails to commit the updated certificate keys to NVRAM. The background service enters a repetitive retry loop, causing high kernel lockups, network stack stalls, or total UI freezes.

  • Current Microsoft Acknowledgment & Status:

    • Microsoft has published technical troubleshooting frameworks for Secure Boot servicing but has not officially added this specific hard-freeze behavior to the official Known Issues health dashboard for Windows 10 or Windows 11.

    • Because the issue appears to stem from a conflict between OS-level certificate writes and legacy motherboard firmware behavior rather than a universal OS bug, it primarily impacts older devices whose original equipment manufacturers have ceased active BIOS updates.

 

Source: Neowin 

💬 AI Content Assistant

Ask me anything about this article. No data is stored for your question.

Comments