Keys can be added to the whitelist or the blacklist by updating the DB or DBX variables. Doing that requires that the update be signed by a valid KEK. Windows 8 logo machines will have a Microsoft key in KEK, so Windows Update can certainly add keys to either.