Users are unable to RDP to Windows virtual servers.
Windows Device Manager displays a warning for the device `EFI firmware for host`.
Error message: `This device cannot start. (Code 10) Windows cannot verify the digital signature for this file.`
Virtual machine is running on ESXi 8.0.3 or higher.
VMware vSphere ESXi 8.x
VMware Tools 12.5.x or 13.0.x
Windows Guest OS (Windows 10, Windows 11, Server 2019, Server 2022)
vTPM device present
The `EFIFW` driver in the affected VMware Tools versions is signed using only SHA-1.
Modern Windows operating systems have deprecated SHA-1 and require SHA-256 signatures for driver verification.
Consequently, Windows blocks the driver from starting.
Fixed in VMware Tools 13.1.0 and higher. See Download Broadcom products and software for steps to download this release.
Workaround:
To remediate the device error manually, perform the following steps:
1. Shut down the virtual machine.
2. Enable Secure Boot in the VM settings under Boot Options.
3. Power on the virtual machine.
4. Verify the `EFI firmware for host` device status in Device Manager.
5. (Optional) If Secure Boot must be disabled, shut down the VM, disable Secure Boot, and restart.
Alternatively, removing and re-adding the vTPM device or performing a clean re-installation of VMware Tools may resolve the issue.
For further updates on this defect, please subscribe to this article Instructions to subscribe to an article