KB5051979: Windows Server 2022 Security Update (OS Build 20348.3207) - February 2025
February 11, 2025 security update for Windows Server 2022, bringing OS build 20348.3207 with fixes for Task Manager, USB audio, Device Health Attestation, and more.

Summary
This is the February 11, 2025 monthly security update for Windows Server 2022, released as KB5051979 and bringing the OS to build 20348.3207. It is a security-class cumulative update that addresses multiple quality and reliability issues. Full details are available from Microsoft Support.
Improvements and fixes
- Task Manager CPU index: Corrects an issue where the CPU index number could display incorrectly when setting process affinity on servers with two or more non-uniform memory access (NUMA) nodes.
- GB18030-2022 standard: Adds support for the GB18030-2022 amendment, expanding character set compliance.
- Memory leak: Resolves a memory leak that occurred when predictive input suggestions were displayed.
- Device Health Attestation: Fixes a problem introduced when upgrading from Windows Server 2016 where a required component was missing, causing the attestation service to fail.
- Windows Kernel Vulnerable Driver Blocklist (DriverSiPolicy.p7b): Expands the list of drivers flagged as at risk for Bring Your Own Vulnerable Driver (BYOVD) attacks.
- Directory enumeration: Fixes a failure that could occur when enumerating a directory containing symbolic links with long target names.
- Bind Filter Driver: Resolves a system hang that could occur when the driver accessed symbolic links.
- USB audio devices (DAC - known issue resolution): Fixes a problem where USB audio devices, particularly those using a DAC driver based on USB 1.0, could stop working and halt playback.
- USB cameras: Corrects an issue introduced by the January 2025 security update where the operating system failed to detect that a USB camera was active.
- USB audio device drivers - Code 10 error: Resolves a "This device cannot start" (Code 10) error that appeared when connecting certain external audio management devices.
Known issues
OpenSSH service fails to start
Symptom: After installing the October 2024 security update, some devices report that the OpenSSH (Open Secure Shell) service fails to start, blocking all SSH connections. The failure produces no detailed log output, and manually running the sshd.exe process is required as an interim step. The issue affects enterprise, IoT, and education customers on a limited number of devices.
Workaround: This issue is addressed in KB5053603.
Citrix Session Recording Agent blocks update installation
Symptom: Devices with Citrix Session Recording Agent (SRA) version 2411 (released December 2024) installed may be unable to complete installation of the January 2025 Windows security update. The update may appear to download and apply correctly, but on restart the device displays a message similar to "Something didn't go as planned. No need to worry - undoing changes" and reverts to the previously installed update state. Home users are not expected to be affected.
Workaround: The issue has been resolved in Citrix Session Recording Agent version 2503, released April 28, 2025, and later versions. Citrix documentation titled "Microsoft's January Security Update Fails/Reverts on a machine with 2411 Session Recording Agent" provides additional detail.
System Guard Runtime Monitor Broker service error in Event Viewer
Symptom: On devices that have installed Windows updates released January 14, 2025, or later, Windows Event Viewer may show Event ID 7023 under Windows Logs > System, with text similar to "The System Guard Runtime Monitor Broker service terminated with the following error: %%3489660935". The error is silent - it does not appear as a dialog or notification - and Microsoft states there is no impact to performance, functionality, or security level. The SgrmBroker.exe service was originally created for Microsoft Defender but no longer plays an active role. Microsoft advises against manually starting, uninstalling, or removing this service or its components.
Workaround: This issue is addressed in KB5055526.
How to get this update
Before installing, confirm that your OS image includes KB5030216 (released 09/12/2023) or a later cumulative update when servicing offline images. Without it, the SSU version may be below 20348.1960, which can trigger error 0x800f0823 (CBS_E_NEW_SERVICING_STACK_REQUIRED). Microsoft now combines the latest servicing stack update (SSU) - in this case KB5050117, version 20348.3081 - with the cumulative update in a single package.
This update is available through the following channels:
- Windows Update / Microsoft Update: Downloads and installs automatically; no manual steps required.
- Windows Update for Business: Deploys automatically in line with configured policies.
- Microsoft Update Catalog: Standalone package available for manual download.
- Windows Server Update Services (WSUS): Syncs automatically when Products and Classifications are set to Product: Microsoft Server operating system-21H2 and Classification: Security Updates.
To remove only the cumulative update portion after installation, use the DISM /online /remove-package command with the LCU package name as the argument. Running wusa.exe /uninstall against the combined package will not work because the SSU component cannot be removed after installation.
Frequently asked questions
Does this update include a servicing stack update?
Yes. Microsoft bundles the latest servicing stack update (SSU) for Windows Server 2022 - KB5050117 at version 20348.3081 - together with this cumulative update. You do not need to install the SSU separately before applying KB5051979 in most scenarios.
What is the minimum prerequisite for offline image servicing?
For offline OS image servicing, the image must already include KB5030216 (released 09/12/2023) or a later cumulative update. That release brings the SSU to version 20348.1960, which is the minimum required to avoid error 0x800f0823 during update application.
Can I uninstall this update if something goes wrong?
You can remove the cumulative update (LCU) portion using DISM /online /remove-package and specifying the LCU package name found via DISM /online /get-packages. However, because this package combines the SSU and LCU, using wusa.exe /uninstall will not work, and the SSU portion cannot be removed once installed.
Where can I find the full list of security vulnerabilities addressed?
Microsoft does not enumerate every CVE within the KB article itself. For a complete list of security vulnerabilities covered by this update, consult the Security Update Guide and the February 2025 Security Updates release notes published separately by Microsoft.



