Windows virtual machines with VMware Tools versions 12.5.0 and 13.0.0 has warning on Device manager for device 'EFI firmware for host'
search cancel

Windows virtual machines with VMware Tools versions 12.5.0 and 13.0.0 has warning on Device manager for device 'EFI firmware for host'

book

Article ID: 412721

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

Users are unable to RDP to Windows virtual servers.
Windows Device Manager displays a warning for the device `EFI firmware for host`.
Error message: `This device cannot start. (Code 10) Windows cannot verify the digital signature for this file.`
Virtual machine is running on ESXi 8.0.3 or higher.

Environment

VMware vSphere ESXi 8.x
VMware Tools 12.5.x or 13.0.x
Windows Guest OS (Windows 10, Windows 11, Server 2019, Server 2022)
vTPM device present

Cause

The `EFIFW` driver in the affected VMware Tools versions is signed using only SHA-1. 
Modern Windows operating systems have deprecated SHA-1 and require SHA-256 signatures for driver verification. 
Consequently, Windows blocks the driver from starting.

Resolution

Fixed in VMware Tools 13.1.0 and higher. See  Download Broadcom products and software for steps to download this release.

Workaround: 

To remediate the device error manually, perform the following steps:
1. Shut down the virtual machine.
2. Enable Secure Boot in the VM settings under Boot Options.
3. Power on the virtual machine. 
4. Verify the `EFI firmware for host` device status in Device Manager.
5. (Optional) If Secure Boot must be disabled, shut down the VM, disable Secure Boot, and restart.

Alternatively, removing and re-adding the vTPM device or performing a clean re-installation of VMware Tools may resolve the issue.

For further updates on this defect, please subscribe to this article Instructions to subscribe to an article