KB5051987: Windows 11 version 24H2 Security Update (OS Build 26100.3194) - February 2025
February 11, 2025 cumulative security update for Windows 11 version 24H2, delivering OS Build 26100.3194 with miscellaneous internal security improvements.

Summary
KB5051987 is the February 11, 2025 cumulative security update for Windows 11 version 24H2, producing OS Build 26100.3194. Released on February 11, 2025, it addresses security issues in the Windows operating system and incorporates improvements previously shipped in KB5050094 (January 28, 2025). See Microsoft Support for the official page.
Highlights
- This update addresses security issues for the Windows operating system.
Improvements and fixes
- Carries forward all improvements included in KB5050094, released January 28, 2025.
- Applies miscellaneous security improvements to internal OS functionality. Microsoft documented no additional issues or new features for this release beyond those security improvements.
- Bundles the Windows 11 servicing stack update KB5052085, which brings the servicing stack to build 26100.3189, improving the reliability of the component responsible for installing Windows updates.
Known issues
Roblox unavailable on Arm devices
Symptom: Players on Arm-based devices cannot download and play Roblox from the Microsoft Store on Windows.
Workaround: Roblox is working on a fix. Until it is available, players on Arm devices can play by downloading the title directly from www.Roblox.com. Check the Roblox support site for progress updates.
OpenSSH service fails to start
Symptom: After installing the October 2024 security update, some customers report that the OpenSSH (Open Secure Shell) service fails to start, blocking SSH connections. The failure produces no detailed log output, and manual intervention is required to run sshd.exe. This affects enterprise, IoT, and education customers on a limited number of devices; impact on Home and Pro consumer editions is still under investigation.
Workaround: This issue is addressed in KB5052093.
Citrix Session Recording Agent blocks January 2025 update installation
Symptom: Devices with Citrix Session Recording Agent (SRA) version 2411 (released December 2024) installed may fail to complete installation of the January 2025 Windows security update. The update may initially appear to download and apply correctly, but on restart the device displays a message similar to "Something didn't go as planned. No need to worry - undoing changes" and reverts to the previously installed Windows updates. This issue is expected to affect only a limited number of organizations. Home users are not expected to be affected.
Workaround: The issue has been resolved in Citrix Session Recording Agent version 2503, released April 28, 2025, and later versions. Citrix documentation titled "Microsoft's January Security Update Fails/Reverts on a machine with 2411 Session Recording Agent" provides additional details.
Remote Desktop sessions freeze after connection
Symptom: After installing KB5050094 (January 21, 2025) or later updates on Windows 11 version 24H2, Remote Desktop sessions may freeze shortly after connecting. Mouse and keyboard input become unresponsive inside the session, requiring a disconnect and reconnect.
Workaround: This issue is addressed in KB5052093.
Remote Desktop sessions disconnect unexpectedly
Symptom: After installing KB5050094 or later updates, users may experience unexpected RDP session disconnections, including Remote Desktop Services (RDS) sessions. Reports increased significantly after the March 2025 security update (KB5053598). RDP sessions may drop after approximately 65 seconds when using UDP-based connections from Windows 11 version 24H2 devices to RDS hosts running Windows Server 2016 or earlier. Note: Windows Server 2025 is not affected as an RDS host but may experience disconnects when acting as an RDP client connecting to older servers.
Workaround: This issue is addressed in KB5053656 (released March 27, 2025). IT admins managing devices that have already installed KB5053656 or a later update do not need to apply a Known Issue Rollback (KIR) or special Group Policy. For devices on an earlier update, admins can deploy the special Group Policy found under Computer Configuration > Administrative Templates using the Known Issue Rollback mechanism. The specific policy package is "Windows 11 24H2 and Windows Server 2025 KB5053598 250314_20401 Known Issue Rollback." After deploying the policy, a device restart is required. This Group Policy resolves the issue caused by updates released in January, February, and March 2025.
How to get this update
Microsoft combines the latest servicing stack update (SSU) with the cumulative update in a single package, so no separate SSU installation step is needed before applying this update.
- Windows Update and Microsoft Update: The update downloads and installs automatically. No additional steps are required.
- Windows Update for Business: The update deploys automatically in accordance with configured policies.
- Microsoft Update Catalog: Download the standalone package directly from the Microsoft Update Catalog site. The package contains MSU files that must be installed in order. You can install all MSU files together using DISM with the
/Add-Packageflag and pointing/PackagePathat the folder containing the files, or install them individually in the following sequence: firstwindows11.0-kb5043080-x64, thenwindows11.0-kb5051987-x64. - Windows Server Update Services (WSUS): The update syncs automatically when the WSUS product is set to Windows 11 and the classification is set to Security Updates.
To remove only the cumulative update after installation, use DISM /online /remove-package with the LCU package name. Running wusa.exe /uninstall against the combined package will not work because the SSU is embedded in it and cannot be removed after installation.
Frequently asked questions
Does this update include fixes from the January 2025 preview update?
Yes. KB5051987 incorporates all improvements that shipped in KB5050094, the January 28, 2025 preview update. If that earlier update is already installed on a device, only the new content in KB5051987 will be downloaded and applied.
Is a separate servicing stack update required before installing KB5051987?
No separate pre-installation step is needed. Microsoft packages the servicing stack update (KB5052085, build 26100.3189) together with the cumulative update, so both components install in a single operation.
Does this update apply to Microsoft Store apps?
No. Windows updates distributed through this channel do not install Microsoft Store application updates. Enterprise admins should consult the Microsoft Store apps - Configuration Manager documentation; consumer users should use the Get updates for apps and games in Microsoft Store process.
How can admins deploy this update to offline or media-based environments?
Admins can apply KB5051987 to mounted Windows installation media using DISM with the /Add-Package option or the Add-WindowsPackage PowerShell cmdlet. When downloading additional Dynamic Update packages to pair with this update, ensure they match the same monthly release. If a matching SafeOS or Setup Dynamic Update is unavailable for February 2025, use the most recently published version of each.









