Latest Windows 2022 Server Update Causes BSODs on AMD EPYC With VBS Enabled

Inspur
(Image credit: Inspur)

Neowin reports that Microsoft's latest Windows Server 2022 update, KB5031364, is triggering blue screens of death on VMware ESXi hypervisors running on AMD's EPYC server CPUs. Microsoft confirms that the issue is partially related to Virtualization Based Security (VBS) being enabled in Windows Server 2022, which is a feature known to cause stability issues in the past. If you've installed this update, Microsoft recommends disabling "Expose IOMMU to guest OS" to work around the issue.

Specifically, this new bug affects the start-up procedure on guest VM's running on VMware's ESXi hypervisor. When a startup failure occurs, users can expect an error code to pop up featuring the words "PNP Detected Fatal Error." According to Microsoft's notes, VM servers with the update can expect the problem to occur if you have the following: an AMD EPYC server CPU, "Expose IOMMU to guest OS" enabled in VMware settings for the VM, and have both “Enable Virtualization Based Security” and "System Guard Secure Launch" enabled on guest hosts running Windows Server 2022.

Latest Videos FromTom's Hardware
TOPICS
Aaron Klotz
Contributing Writer

Aaron Klotz is a contributing writer for Tom’s Hardware, covering news related to computer hardware such as CPUs, and graphics cards.

  • tamalero
    is VBS really that required "feature"? I mean, if its this unstable...
    Reply
  • TechieTwo
    Microsoft is in the wrong business IMNHO.
    Reply
  • sjkpublic
    Here come the lawyers. This is a good one. MS changes taking out a major competitor and seizing control of a major virtualization market. All in the name of security. Wouldnt it be nice if the OS was written for security instead of dealing with 3rd party contracts?
    Reply
  • rluker5
    A specific series of CPUs somehow working in an incompatible fashion with what was likely assumed by the software engineers as a safe improvement to make might be indicative of an exploitable security vulnerability of those specific CPUs. They are handling virtualization based security differently than the rest.
    It is a normal feature of Windows that showed up in the latest Windows Server. And even if Windows can get the basic security feature working normally on Epyc, those chips known malfunction with specific code might be exploitable, maybe. Might be an I/O die thing.
    Reply