
Just completed the full CVE-2023-24932 remediation on an enterprise Lenovo device. All four mitigations done. FirmwareSVN: 7.0. Compliant. Here is what most people do not know: the Intune Settings Catalog policy and Microsoft's 2026 Secure Boot playbook only cover mitigations 1-2 (certificate deployment). Mitigations 3-4 (2011 CA revocation and SVN enforcement) are a separate step that is not documented in any of the 2026 guidance. The cmdlet to verify it (Get-SecureBootSVN) was quietly added in KB5077241 with two sentences in the changelog. Your device can show Event 1808, UEFICA2023Status Updated, Capable 2, and still be SVN non-compliant. I am running a Secure Boot workshop on April 8. If you want to understand the full picture and not just what the playbook tells you, join me there. Register here: https://docs.kaidojarvemets.com/training/secure-boot-workshop
Post summary
The author has fully remediated CVE‑2023‑24932 on a Lenovo device, highlighting that four mitigations exist, two of which are not covered in standard guidance, and invites a workshop to discuss the complete mitigation picture.








