BIOS & startup · high

How to fixUEFI-SECURE-BOOT-DB-EXPIRED

UEFI Secure Boot database entry expired

What this error means

UEFI-SECURE-BOOT-DB-EXPIRED is a high-severity hardware BIOS/UEFI problem. A Secure Boot signature in the UEFI signature database (db) has expired. Microsoft has been revoking old Secure Boot certificates as part of CVE mitigations (e.g., Black Lotus bootkit fix). After a BIOS or Windows update applies the revocation, previously trusted bootloaders or recovery media become untrusted, preventing boot. See the troubleshooting steps below for the fix.

Before you begin

Save open work and back up important files. Use instructions for your exact device and software version. If Windows cannot start, see the startup guide.

Work through these checks

0 of 3 complete
01Update UEFI Secure Boot database via Windows Update
  1. Update UEFI Secure Boot database via Windows Update
What to expect

Check whether the original symptom still occurs.

If it does not help

Continue only if this check applies to your device. Consult its manufacturer if you are unsure.

Browse related errors
02Regenerate Secure Boot keys in BIOS
  1. Regenerate Secure Boot keys in BIOS
What to expect

Check whether the original symptom still occurs.

If it does not help

Continue only if this check applies to your device. Consult its manufacturer if you are unsure.

Browse related errors
03Update or recreate bootable USB media
  1. Update or recreate bootable USB media
What to expect

Check whether the original symptom still occurs.

If it does not help

Continue only if this check applies to your device. Consult its manufacturer if you are unsure.

Browse related errors

Possible causes

  • Microsoft Secure Boot certificate revocation (KB5025885)
  • Outdated dual-boot Linux EFI bootloader
  • Old USB recovery media with expired signatures