Latest Microsoft Patch can leave VMs unbootable
Just ran across this myself in the lab I teach vSphere Workshops.
All of the Windows VMs are Windows Server 2022.
I patched them all and rebooted the VMs during the patching (as normal).
After shutting them all down to do a backup (yes, that’s my process for the lab), I completed the backup.
Powering on the VMs left me with a message
“Windows Boot Manager…Security Violation”
I could get them to boot, but I had to disable Secure Boot in the Boot Options section of the VM’s settings.
Wouldn’t you know it, it’s a problem with ESX 6.7 or 7.0.
ESXi 8.0 is unaffected.
Resolution is to upgrade ESXi 7.0 to Update 3k (released Feb 21).
Which means I updated my vCenter first.
Once updated to ESXi 7.0 Update 3k, Windows 2022 booted up just fine.
VMware KB 90947 is here.
More Ransomware for ESXi…
…and here is CISA’s guidance on ESXiArgs…