Doesn that mean that the system catalog has to change every time Microsoft issues a hotfix for a protected system file?
That’s correct. When Microsoft packages a Service Pack or hotfix that changes protected system files, the package includes not only the protected system files but also a new signed supplemental system catalog file. The hotfix or Service Pack installation procedure verifies the signature on the supplemental catalog file, installs the new supplemental catalog file in parallel to the old system catalog file, and then verifies the hashes of any new protected system files that are included with the hotfix or Service Pack.