NAVANEM
Preview / optionalOS build 26100.3403

March 11 2025 Hotpatch Public Preview KB5053636 (OS Build 26100.3403)

Hotpatch public preview update for Windows 11 Enterprise LTSC 2024, OS build 26100.3403, released March 11, 2025. Fixes x64 app crashes on Arm64 devices.

KB5053636: March 11 2025 Hotpatch Public Preview KB5053636 (OS Build 26100.3403) — navanem Microsoft KB cover
KB5053636 · Windows 11 · Preview Update

Summary

KB5053636 is a hotpatch public preview update for Windows 11 Enterprise LTSC 2024, bringing the OS to build 26100.3403. Released on March 11, 2025, it addresses a specific crash affecting x64 applications on Arm64 hardware introduced by the previous hotpatch cycle. See the full release notes at Microsoft Support.

Improvements and fixes

  • Fixes a problem where certain x64 applications stopped responding or restarted unexpectedly on Arm64 devices after the February 11, 2025 hotpatch update KB5052105 was installed. Microsoft notes that a device restart may be required after installing this 3B hotpatch update (KB5053636) to prevent the issue from recurring.

Known issues

Microsoft lists no known issues for this update at the time of writing.

How to get this update

Before you install

Microsoft now bundles the latest servicing stack update (SSU) with the hotpatch package. If you install through Windows Update, the SSU is applied automatically alongside KB5053636. The SSU for this release is KB5052915, version 26100.3321.

Prerequisites

Before deploying KB5053636, confirm the following conditions are met on each target device:

  • The device must be running Windows 11, version 24H2. The required baseline is KB5050009 (OS version 10.0.26100.2894), dated January 14, 2025. Devices already on the previous hotpatch KB5052105 (OS version 10.0.26100.3107) also qualify.
  • Virtualization-based security (VBS) must be enabled. Without VBS active, the device will not be offered hotpatch updates. Microsoft points administrators to the Memory integrity and VBS enablement documentation for guidance.
  • On Windows Arm64 devices specifically, a registry key must be set before installation to ensure those devices remain fully secure when receiving hotpatch updates. The key stops the OS from loading Compiled Hybrid Portable Executable (CHPE) binaries:
    • Key: HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
    • Value: DWORD: HotPatchRestrictions=1
    • A restart is required after setting this key. The setting persists, so it only needs to be configured once per device.

Installation channels

KB5053636 is available through the following Microsoft release channels:

  • Windows Update / Microsoft Update - downloads and installs automatically.
  • Microsoft Update Catalog - available for manual download.
  • Server Update Services (WSUS) - available for enterprise deployment.

Frequently asked questions

Does this update require a restart?

Microsoft states that a restart may be needed after installing KB5053636, specifically to ensure the x64 application crash fix on Arm64 devices takes full effect. Additionally, if you configure the required HotPatchRestrictions registry key on Arm64 hardware for the first time, a restart is mandatory before the protection applies.

What baseline is required before installing KB5053636?

Devices must be running Windows 11, version 24H2, with at minimum KB5050009 (OS build 10.0.26100.2894) from January 14, 2025 installed as the baseline. Devices already updated to the February 2025 hotpatch KB5052105 (OS build 10.0.26100.3107) also meet the prerequisite and will receive only the new content in this package.

Does VBS need to be enabled for hotpatch updates to apply?

Yes. Virtualization-based security must be turned on for a device to receive hotpatch updates. If VBS is not already active, Microsoft directs administrators to enable it by consulting the Memory integrity and VBS enablement documentation before attempting to deploy this or any hotpatch update.

Is the servicing stack update included in this package?

Yes. Microsoft now combines the latest SSU with the hotpatch update package. When installing through Windows Update, the SSU (KB5052915, version 26100.3321) installs automatically. Administrators deploying via the Catalog or WSUS should review the file information provided on the support page to confirm all components are accounted for.

#hotpatch#windows-11#arm64#ltsc-2024#security-update#vbs#servicing-stack

Related topics