NAVANEM
Security updateOS build 26100.2894

KB5050009 - Windows 11 24H2 Security Update (OS Build 26100.2894)

January 14, 2025 security update for Windows 11 version 24H2, delivering OS Build 26100.2894. Addresses kernel vulnerable driver blocklist and includes a bundled servicing stack update.

KB5050009: Windows 11 24H2 Security Update (OS Build 26100.2894) — navanem Microsoft KB cover
KB5050009 · Windows 11 · Security Update

Summary

KB5050009 is the January 14, 2025 monthly security update for Windows 11 version 24H2. It produces OS Build 26100.2894 and ships alongside a bundled servicing stack update (KB5050387, build 26100.2890). The update addresses security issues in the Windows operating system. Source: Microsoft Support.

Highlights

  • This update addresses security issues for the Windows operating system.

Improvements and fixes

  • Windows Kernel Vulnerable Driver Blocklist (DriverSiPolicy.p7b): The update expands the list of drivers flagged as risks for Bring Your Own Vulnerable Driver (BYOVD) attacks, adding newly identified at-risk drivers to the blocklist.
  • This update incorporates all improvements previously delivered in KB5048667, released December 10, 2024. Devices that already have that update installed will only download and apply the new changes included in this package.
  • A bundled servicing stack update, KB5050387 (build 26100.2890), is included to improve the reliability and quality of the component responsible for installing Windows updates.

Known issues

Roblox unavailable on Arm devices via Microsoft Store

Symptom: Players on Arm-based devices are unable to download and play Roblox through the Microsoft Store on Windows.

Workaround: Players on Arm devices can play Roblox by downloading it directly from www.Roblox.com.

OpenSSH service fails to start after October 2024 security update

Symptom: Following installation of the October 2024 security update, some customers report that the OpenSSH (Open Secure Shell) service fails to start, preventing SSH connections. The service fails with no detailed logging, and manual intervention is required to run the sshd.exe process. This affects enterprise, IoT, and education customers, with a limited number of devices impacted.

Workaround: This issue is addressed in KB5052093.

Citrix Session Recording Agent 2411 blocks update installation

Symptom: Devices with Citrix Session Recording Agent (SRA) version 2411 installed may be unable to complete installation of the January 2025 Windows security update. The update may initially download and apply correctly, but on restart an error similar to "Something didn't go as planned. No need to worry - undoing changes" appears and the device reverts to the previously installed Windows update. This issue is expected to affect only a limited number of organizations, as version 2411 is a new release. Home users are not expected to be affected.

Workaround: The issue has been resolved in Citrix Session Recording Agent version 2503, released April 28, 2025, and newer versions. See Citrix documentation titled "Microsoft's January Security Update Fails/Reverts on a machine with 2411 Session Recording Agent" for details.

USB audio devices stop working after update

Symptom: After installing this security update, USB audio devices may stop working and prevent audio playback. The issue is more likely to occur when using a USB 1.0 audio driver based DAC (Digital to Analog Converter). Device Manager may display the error "This device cannot start. (Code 10) Insufficient system resources exist to complete the API."

Workaround: This issue is addressed in KB5050094.

USB cameras not recognized after update

Symptom: After installing this security update, USB cameras may not be recognized as active by the device.

Workaround: This issue is addressed in KB5050094.

How to get this update

Microsoft combines the latest servicing stack update (SSU) with the latest cumulative update (LCU) in a single package, so no separate SSU installation step is required before applying this update.

  • Windows Update and Microsoft Update: The update downloads and installs automatically. No manual steps are required.
  • Windows Update for Business: The update syncs automatically in accordance with configured policies.
  • Microsoft Update Catalog: Download the standalone package directly from the Microsoft Update Catalog. The package contains more than one MSU file that must be installed in order. You can install all MSU files together using DISM with the /Add-Package option pointing to the folder containing all files, or install each MSU individually in the correct sequence: first windows11.0-kb5043080-x64, then windows11.0-kb5050009-x64.
  • Windows Server Update Services (WSUS): The update syncs automatically when Products and Classifications are configured as Product: Windows 11, Classification: Security Updates.

To remove the LCU after installation, use the DISM /online /remove-package command with the LCU package name as the argument. Running wusa.exe /uninstall against the combined package will not work because the SSU is embedded and cannot be removed after installation.

Frequently asked questions

Does this update include changes from previous cumulative updates?

Yes. KB5050009 incorporates all improvements previously shipped in KB5048667, released December 10, 2024. If your devices already have that update installed, only the incremental changes in this package will be downloaded and applied, keeping bandwidth usage to a minimum.

Is a separate servicing stack update required before installing KB5050009?

No separate step is needed. Microsoft bundles the servicing stack update KB5050387 (build 26100.2890) directly into this package. The combined package handles the SSU installation automatically before applying the cumulative update.

What should IT admins do about the Citrix Session Recording Agent conflict?

Admins should verify whether any managed devices have Citrix Session Recording Agent version 2411 installed. If affected devices are reverting the January 2025 update, the resolution is to upgrade the Citrix SRA to version 2503 or later, released April 28, 2025, before reattempting the Windows update.

How can the LCU be removed if needed after installation?

Use DISM /online /get-packages to identify the exact LCU package name, then run DISM /online /remove-package with that name. The wusa.exe /uninstall method does not work for this combined SSU and LCU package because the servicing stack component cannot be removed once installed.

#windows-11#24h2#security-update#cumulative-update#driver-blocklist#servicing-stack#known-issues

Related topics