BIOS & startup · high

How to fixUEFI-SECURE-BOOT-DB-EXPIRED

UEFI Secure Boot database entry expired

What this error means

UEFI-SECURE-BOOT-DB-EXPIRED is a high-severity hardware BIOS/UEFI problem. A Secure Boot signature in the UEFI signature database (db) has expired. Microsoft has been revoking old Secure Boot certificates as part of CVE mitigations (e.g., Black Lotus bootkit fix). After a BIOS or Windows update applies the revocation, previously trusted bootloaders or recovery media become untrusted, preventing boot. See the troubleshooting steps below for the fix.

Before you begin

Save open work and back up important files. Note any recent driver or hardware changes. If Windows cannot start, use the startup guide first.

Work through these checks

0 of 3 complete
01Update UEFI Secure Boot database via Windows Update

Update UEFI Secure Boot database via Windows Update.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
02Regenerate Secure Boot keys in BIOS

Regenerate Secure Boot keys in BIOS.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
03Update or recreate bootable USB media

Update or recreate bootable USB media.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help

Possible causes

  • Microsoft Secure Boot certificate revocation (KB5025885)
  • Outdated dual-boot Linux EFI bootloader
  • Old USB recovery media with expired signatures