Update: I was able to enroll my own keys using the UEFI menu instead of KeyTool. UEFI ver. 1.11. Lenovo still hasn't even acknowledged the issue that I know of so I'd assume it's still possible to brick the motherboard this way. Make sure to do everything in the right order (PK last!). Any attempt is at your own risk as Lenovo considers it customer induced damage if it goes wrong.