> Source: [sk185067](https://support.checkpoint.com/results/sk/sk185067)

# sk185067 - FDE BSOD 0xc000000f or Pre-boot RSOD ERR_NULL (0x5001678) After Windows Updates KB5062713 / KB5087420

| Property | Value |
|----------|-------|
| Solution ID | sk185067 |
| Date Created | 2026-06-17 |
| Last Modified | 2026-08-05 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | E89.X, E88.X |
| Platform | Intel/PC |

## Symptoms

- * Pre-boot Red Screen (RSOD) with ERR_NULL (0x5001678)
* Blue Screen of Death (BSOD) with Stop Code 0xc000000f
* Corrupted ESP (EFI System Partition)
* During UEFI boot, this error message appears: `Load Image Failed with Status Not Found`

## Cause

Microsoft updates UEFI Secure Boot certificates through Windows Updates **KB5062713** and **KB5087420**. As part of the update:

1. Windows runs the **Secure-Boot-Update** task.
2. The task updates the boot manager file **bootmgfw.efi**.

Check Point Full Disk Encryption (FDE) also interacts with the same file during pre-boot.

Under normal conditions, both operations complete successfully. However, an issue can occur when:

* The update process is in progress, and
* The device enters hibernation before completion

During resume:

1. FDE modifies the EFI System Partition (ESP).
2. The hibernation image restores an outdated Windows view of the ESP.
3. Windows writes outdated data back to disk.

This causes file system inconsistency (for example, duplicate or cross-linked boot files).  
As a result, the device may fail to boot.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
