NAVANEM
Security updateOS build 26100.3107

February 11 2025 Hotpatch Public Preview KB5052105 (OS Build 26100.3107)

Hotpatch public preview security update for Windows 11 Enterprise LTSC 2024, releasing OS build 26100.3107 on February 11, 2025.

KB5052105: February 11 2025 Hotpatch Public Preview KB5052105 (OS Build 26100.3107) — navanem Microsoft KB cover
KB5052105 · Windows 11 · Security Update

Summary

KB5052105 is a hotpatch public preview security update for Windows 11 Enterprise LTSC 2024, producing OS build 26100.3107. Released on February 11, 2025, it delivers miscellaneous security improvements to internal OS functionality. Full details are available on the Microsoft Support page.

Improvements and fixes

  • This update applies miscellaneous security improvements to internal OS functionality. Microsoft documents no additional issues or new features for this release.

Known issues

Microsoft lists no known issues for this update at the time of writing.

How to get this update

Prerequisites

Before installing KB5052105, confirm that all of the following conditions are met:

  • Your device must run Windows 11, version 24H2, with KB5050009 (dated January 14, 2025) already installed.

  • Virtualization-based security (VBS) must be enabled on the device. This ensures hotpatch updates install more securely.

  • On Windows ARM based devices only, you must set the following registry key before installing. This stops the OS from loading Compiled Hybrid Portable Executable (CHPE) binaries and ensures those devices are fully secure when hotpatch updates are applied.

    Key: HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management

    DWORD: HotPatchRestrictions=1

    Restart the computer after setting this key. Once set, the value persists and does not need to be set again.

Servicing stack

Microsoft now combines the latest servicing stack update (SSU) with the hotpatch update package. When you use Windows Update, the latest SSU is installed automatically alongside this update. The associated SSU is KB5052085, version 26100.3189.

Delivery channels

KB5052105 is available through the following channels:

  • Windows Update - the update downloads and installs automatically; no additional steps are required.
  • Microsoft Update Catalog - manual download available.
  • Server Update Services (WSUS) - available for organizations using WSUS-based deployment.

Frequently asked questions

What is a hotpatch update and how does it differ from a standard cumulative update?

A hotpatch update applies security fixes to the running OS image in memory, which means the device can receive the patch without requiring an immediate restart in most cases. Standard cumulative updates typically require a restart to complete installation. Hotpatch is currently in public preview for Windows 11 Enterprise LTSC 2024.

Why must virtualization-based security (VBS) be enabled before installing this update?

Microsoft requires VBS to be active because it provides the security isolation that hotpatch relies on to apply code changes safely. Without VBS enabled, the hotpatch mechanism cannot guarantee that patches are applied in a fully secure manner, and installation will not proceed as expected.

Is the extra registry key required on all devices, or only on ARM based hardware?

The registry key HotPatchRestrictions=1 is required only on Windows ARM based devices. It prevents the OS from loading CHPE binaries, ensuring those devices remain fully secure during hotpatch installation. Devices running on x64 hardware do not need this key.

Do I need to download the servicing stack update separately before applying KB5052105?

No. Microsoft bundles the latest SSU (KB5052085, version 26100.3189) with this hotpatch update. If you are using Windows Update, the SSU installs automatically as part of the same operation, so no separate SSU download step is needed.

#hotpatch#windows-11#ltsc-2024#security-update#vbs#servicing-stack#public-preview

Related topics