Windows Server updates

Winsage
July 10, 2025
Microsoft released patches for 130 vulnerabilities in the July 2025 Patch Tuesday update. Notable vulnerabilities include CVE-2025-49719, an uninitialized memory disclosure in Microsoft SQL Server, and CVE-2025-47981, a wormable remote code execution flaw in Windows. CVE-2025-49719 is assessed as having "unproven" exploit code, while CVE-2025-47981 has a high likelihood of exploitation within 30 days. Other vulnerabilities include CVE-2025-49717, a buffer overflow in SQL Server, and CVE-2025-49704, which allows code injection in SharePoint. Additionally, updates address vulnerabilities in Windows Routing and Remote Access Service (RRAS) and Microsoft Edge, including CVE-2025-6554, which has been actively exploited. Administrators are advised to prioritize patching internet-facing assets and consider additional mitigations for RRAS vulnerabilities.
Winsage
June 16, 2025
Microsoft has acknowledged that the June security update has caused complications for users of Windows Server systems, specifically affecting the Dynamic Host Configuration Protocol (DHCP) service, which is failing and leading to improper functioning of IP refreshes. The issue impacts multiple versions of Windows Server, including 2016 (KB5061010), 2019 (KB5060531), 2022 (KB5060526), and 2025 (KB5060842). Users have reported that the DHCP service may stop responding after installing the update, with one administrator noting their 2016 server crashed shortly after the update was applied. Microsoft is working on a solution and advises affected users to uninstall the update to restore functionality. The company has a history of DHCP-related issues dating back over a decade and has faced other problems with Windows Server updates in the past year, including issues with keyboard and mouse inputs and authentication challenges.
Winsage
August 14, 2024
Microsoft resolved an issue affecting Microsoft 365 Defender (Defender XDR) that arose after the July 2024 Windows Server updates, specifically impacting Windows Server 2022 and disrupting the Network Detection and Response (NDR) service. This disruption also affected other Defender functionalities reliant on NDR, such as Incident Response and Device Inventory. The issue was addressed by Windows updates released on August 13, 2024 (KB5041160) and later. Users are advised to install the latest updates for crucial improvements. Additionally, Microsoft fixed another issue causing LPD printing jobs to fail across Windows Server 2022, 2019, and 2016 systems after the July 2024 updates. An emergency fix was also deployed in May for Windows Server 2019 to resolve 0x800f0982 errors. Earlier in May, Microsoft addressed issues disrupting VPN connections, unexpected reboots of domain controllers, and NTLM authentication failures after April's updates. However, a lingering bug affecting remote desktop connections on Windows Server 2012 and later continues to cause intermittent logon session losses, requiring reconnections.
Winsage
July 15, 2024
Microsoft has provided a workaround for a known issue preventing the Microsoft Photos app from launching on certain Windows 11 systems. The problem affects devices running Windows 11 22H2 and 23H2 with specific policies enabled. Users who updated the app from the Windows store after June 4, 2024, may experience difficulties. To address this, Windows admins are advised to install the latest Windows App SDK released during the July Patch Tuesday as a temporary solution.
Search