NAVANEM
Security updateOS build 22621.5039 and 22631.5039

KB5053602: Windows 11 Security Update for OS Builds 22621.5039 and 22631.5039 (March 2025)

March 11, 2025 security update for Windows 11 versions 22H2 and 23H2, bringing OS builds to 22621.5039 and 22631.5039 with miscellaneous internal OS security improvements.

KB5053602: Windows 11 Security Update for OS Builds 22621.5039 and 22631.5039 (March 2025) — navanem Microsoft KB cover
KB5053602 · Windows 11 · Security Update

Summary

KB5053602 is a security update for Windows 11 versions 22H2 and 23H2, released on March 11, 2025. It brings affected devices to OS builds 22621.5039 and 22631.5039. The update delivers miscellaneous internal OS security improvements and includes quality improvements from the February 25, 2025 update (KB5052094). See the Microsoft Support page for full details.

Improvements and fixes

  • For Windows 11 version 23H2: this release includes all improvements present in Windows 11 version 22H2. No additional issues are documented for this version.
  • For Windows 11 version 22H2: this update delivers miscellaneous security improvements to internal OS functionality. It also incorporates improvements that were part of the February 25, 2025 update (KB5052094). No additional issues are documented beyond those improvements.
  • The latest servicing stack update (SSU) is bundled with this update for devices using Windows Update or WSUS, so no separate SSU installation is required.
  • A separate servicing stack update, KB5052107 (builds 22621.4963 and 22631.4963), improves the quality of the servicing stack - the component responsible for installing Windows updates - to ensure devices can reliably receive and apply Microsoft updates.

Known issues

Citrix Session Recording Agent blocks update installation

Symptom: Devices with certain Citrix components installed - specifically Citrix Session Recording Agent (SRA) version 2411, released in December 2024 - may fail to complete installation of the January 2025 Windows security update. The update may initially appear to download and apply correctly, but on restart an error similar to "Something didn't go as planned. No need to worry - undoing changes" appears and the device reverts to its previous Windows update state. This issue is expected to affect only a limited number of organizations, as SRA version 2411 is a new release. Home users are not expected to be affected.

Workaround: This issue has been resolved in Citrix Session Recording Agent version 2503, released on April 28, 2025, and newer versions. Refer to Citrix documentation titled "Microsoft's January Security Update Fails/Reverts on a machine with 2411 Session Recording Agent" for further details.

USB dual-mode printer prints random text and data

Symptom: After installing this update, enterprise users may experience problems with USB-connected dual-mode printers that support both USB Print and IPP Over USB protocols. Affected printers may unexpectedly print random text, network commands, and unusual characters. The printed output often begins with the header "POST /ipp/print HTTP/1.1" followed by other IPP-related headers. The issue occurs more frequently when the printer is powered on or reconnected to the device after being disconnected.

Workaround: This issue is addressed in KB5053657.

Microsoft Copilot app uninstalled and unpinned from taskbar

Symptom: On some devices, the Microsoft Copilot app is unintentionally uninstalled and unpinned from the taskbar after installing this update. This issue does not affect the Microsoft 365 Copilot app.

Workaround: This issue has been fixed and affected devices are being returned to their original state automatically. Users can also reinstall the app from the Microsoft Store and manually pin it back to the taskbar.

How to get this update

Microsoft combines the latest servicing stack update (SSU) with the latest cumulative update (LCU) in a single package, so no separate SSU installation step is needed before applying this update.

This update is available through the following channels:

  • Windows Update and Microsoft Update: The update downloads and installs automatically.
  • Windows Update for Business: The update deploys automatically in accordance with configured policies.
  • Microsoft Update Catalog: A standalone package can be downloaded directly from the Microsoft Update Catalog.
  • Windows Server Update Services (WSUS): The update syncs automatically when Products is set to Windows 11 and Classification is set to Security Updates.

To remove the LCU after installing the combined SSU and LCU package, use the DISM /online /get-packages command to identify the LCU package name, then use DISM /Remove-Package with that name. Note that running wusa.exe with the /uninstall switch will not work on the combined package, and the SSU component cannot be removed after installation.

Frequently asked questions

Does this update apply to both Windows 11 22H2 and 23H2?

Yes. KB5053602 covers both Windows 11 version 22H2 and version 23H2. Both editions reach build 22621.5039 and 22631.5039 respectively after installation. The 23H2 release also includes all improvements present in the 22H2 portion of this update, with no additional documented changes specific to 23H2.

Do I need to install a servicing stack update separately before applying KB5053602?

No separate SSU installation is required. Microsoft bundles the latest servicing stack update (SSU KB5052107) with this cumulative update. When using Windows Update or WSUS, the SSU installs automatically alongside the LCU as part of the same combined package.

What should I do if one of the known issues - such as the USB printer or Citrix problem - affects my environment?

For the USB dual-mode printer issue, install the fix provided in KB5053657. For Citrix environments running SRA version 2411, upgrade to Citrix Session Recording Agent version 2503 or later. For the Microsoft Copilot app removal issue, the fix is being rolled out automatically, or you can reinstall the app manually from the Microsoft Store.

Where can I find more information about the security vulnerabilities fixed in this update?

Microsoft publishes details about addressed security vulnerabilities in the Security Update Guide and in the March 2025 Security Update release notes. Those resources provide CVE-level detail suitable for security teams assessing risk and planning deployment of this update across managed device fleets.

#windows-11#security-update#22h2#23h2#cumulative-update#march-2025#known-issues

Related topics