NAVANEM
Security updateOS build 22621.4751 and 22631.4751

KB5050021: Windows 11 Security Update - OS Builds 22621.4751 and 22631.4751 (January 2025)

January 14, 2025 security update for Windows 11 versions 22H2 and 23H2, bringing OS builds to 22621.4751 and 22631.4751 with kernel driver blocklist and SSU improvements.

KB5050021: Windows 11 Security Update - OS Builds 22621.4751 and 22631.4751 (January 2025) — navanem Microsoft KB cover
KB5050021 · Windows 11 · Security Update

Summary

KB5050021 is a mandatory security update for Windows 11 versions 22H2 and 23H2, released on January 14, 2025. It advances OS builds to 22621.4751 and 22631.4751. The update addresses security issues in the Windows operating system and includes a bundled servicing stack update (KB5050113). See the Microsoft Support page for full details.

Highlights

  • This update addresses security issues in the Windows operating system.

Improvements and fixes

  • Windows 11, version 23H2: This build includes all improvements present in Windows 11, version 22H2. No additional issues are separately documented for the 23H2 release in this update.
  • Windows Kernel Vulnerable Driver Blocklist (DriverSiPolicy.p7b): The update expands the list of drivers flagged as at-risk for Bring Your Own Vulnerable Driver (BYOVD) attacks, continuing Microsoft's effort to block known-vulnerable drivers at the kernel level.
  • Servicing stack update (KB5050113 - builds 22621.4740 and 22631.4740): A servicing stack update is bundled with this cumulative update. It improves the component responsible for installing Windows updates, helping ensure devices can reliably receive and apply future updates.
  • Quality improvements from KB5048685 (December 10, 2024): The 22H2 portion of this update incorporates improvements previously shipped in December 2024's KB5048685. If earlier updates were already installed, only the new delta content is downloaded and applied.

Known issues

OpenSSH service fails to start after October 2024 security update

Symptom: After installing the October 2024 security update, the OpenSSH (Open Secure Shell) service fails to start, blocking SSH connections. The failure occurs with no detailed logging, and manually running the sshd.exe process is required. The issue affects enterprise, IoT, and education customers on a limited number of devices. Microsoft is investigating impact on Home and Pro consumer editions.

Workaround: This issue is addressed in KB5052094.

Citrix Session Recording Agent 2411 blocks update installation

Symptom: Devices with Citrix Session Recording Agent (SRA) version 2411 (released December 2024) may fail to complete installation of the January 2025 Windows security update. The update may appear to download and apply correctly, but on reboot the device displays an error similar to "Something didn't go as planned. No need to worry - undoing changes" and reverts to the previously installed Windows updates. Home users are not expected to be affected.

Workaround: The issue has been resolved in Citrix Session Recording Agent version 2503, released on April 28, 2025, and newer versions. Refer to Citrix documentation titled "Microsoft's January Security Update Fails/Reverts on a machine with 2411 Session Recording Agent" for further details.

USB audio devices stop working

Symptom: After installing this security update, USB audio devices may stop functioning, preventing audio playback. This is more likely to occur when using a USB 1.0 audio driver-based DAC (Digital to Analog Converter). Device Manager may display the error: "This device cannot start. (Code 10) Insufficient system resources exist to complete the API".

Workaround: This issue is addressed in KB5050092.

USB cameras not recognized

Symptom: After installing this security update, USB cameras may not be recognized as active by the device.

Workaround: This issue is addressed in KB5050092.

How to get this update

Microsoft bundles the latest servicing stack update (SSU) with the latest cumulative update (LCU) in a single package, so no separate SSU installation is required beforehand. The update is available through the following channels:

  • Windows Update and Microsoft Update: The update downloads and installs automatically. No manual steps are needed.
  • Windows Update for Business: The update deploys automatically in line with your organization's configured policies.
  • Microsoft Update Catalog: A standalone package is available for manual download from the Microsoft Update Catalog website.
  • Windows Server Update Services (WSUS): The update syncs automatically when Products is set to "Windows 11" and Classification is set to "Security Updates".

To remove only the LCU after installation, use the DISM /Remove-Package command with the LCU package name as the argument. Running wusa.exe with the /uninstall switch will not work on the combined SSU+LCU package. The SSU component cannot be removed after installation.

Frequently asked questions

Does this update apply to both Windows 11 22H2 and 23H2?

Yes. KB5050021 applies to Windows 11 Enterprise and Education (version 22H2) and all editions of Windows 11 version 23H2. Both reach build 22621.4751 and 22631.4751 respectively after installation. The 23H2 build inherits all 22H2 improvements plus the bundled SSU.

Do I need to install the servicing stack update separately before applying KB5050021?

No. Microsoft combines the servicing stack update (KB5050113) directly with the cumulative update package. Deploying KB5050021 via Windows Update, WSUS, or the Update Catalog installs both components together without any prerequisite sequencing required from the admin.

Will this update install Microsoft Store application updates?

No. Windows updates do not install Microsoft Store app updates. Enterprise users should manage Store app updates through Microsoft Store apps - Configuration Manager. Consumer users can get Store app updates through the Microsoft Store app directly.

How do I upgrade a device to Windows 11, version 23H2 to receive this update on that version?

Use the enablement package KB5027397 to update an eligible device to Windows 11, version 23H2. Once on 23H2, KB5050021 will be offered through the standard Windows Update channels and will apply automatically according to your update policies.

#windows-11#security-update#cumulative-update#22h2#23h2#driver-blocklist#servicing-stack

Related topics