KB5053638: March 2025 Hotpatch for Windows Server 2022 Datacenter Azure Edition (OS Build 20348.3270)
March 11, 2025 hotpatch security update for Windows Server 2022 Datacenter: Azure Edition, bringing OS build 20348.3270 with miscellaneous internal OS security improvements.

Summary
KB5053638 is a hotpatch security update for Windows Server 2022 Datacenter: Azure Edition, released on March 11, 2025, bringing the OS to build 20348.3270. It delivers miscellaneous internal OS security improvements with no additional documented fixes. This update is available through Windows Update, WSUS, and the Microsoft Update Catalog. See Microsoft Support for full details.
Improvements and fixes
- This update applies miscellaneous security improvements to internal OS functionality. Microsoft notes that no additional issues were documented for this release beyond that security hardening work.
Known issues
Microsoft lists no known issues for this update at the time of writing.
How to get this update
Before installing KB5053638, note that Microsoft now bundles the latest servicing stack update (SSU) directly with the hotpatch package. If you are using Windows Update or Windows Server Update Services (WSUS), the latest SSU will be installed automatically alongside this update. The associated SSU is KB5053666, version 20348.3320.
This update is available through the following channels:
- Windows Update / Microsoft Update - downloads and installs automatically.
- Microsoft Update Catalog - available for manual download.
- Windows Server Update Services (WSUS) - syncs automatically when you configure Products and Classifications as follows: Product set to
Server 2022 Hotpatch Categoryand Classification set toSecurity Updates.
For a full list of files included in the cumulative update, download the file information for KB5053638. For the servicing stack file list, download the file information for SSU KB5053666.
Frequently asked questions
What is a hotpatch update and how does it differ from a standard cumulative update?
A hotpatch update applies security fixes to running processes in memory without requiring a system reboot at the time of installation. This reduces planned downtime on production servers. Hotpatches are available specifically for Windows Server 2022 Datacenter: Azure Edition and follow a quarterly baseline-plus-hotpatch cadence managed through Azure.
Does this update require a separate servicing stack update to be installed first?
No separate SSU installation step is needed. Microsoft now combines the latest SSU with the hotpatch package itself. When you install KB5053638 via Windows Update or WSUS, the SSU - KB5053666, version 20348.3320 - is installed as part of the same operation automatically.
How do I configure WSUS to receive this hotpatch update?
In your WSUS console, set the Product to Server 2022 Hotpatch Category and the Classification to Security Updates. Once configured, WSUS will sync KB5053638 automatically. Clients that have already installed earlier updates in this package will only download the new delta content contained in this release.
Which systems are eligible for this hotpatch update?
KB5053638 applies exclusively to Windows Server 2022 Datacenter: Azure Edition. Standard editions of Windows Server 2022 or non-Azure-hosted deployments are not targeted by this hotpatch and would receive security updates through a different cumulative update package.
