NAVANEM
Security updateOS build 20348.3453

KB5055526: Windows Server 2022 Security Update (OS Build 20348.3453) - April 8, 2025

April 8, 2025 cumulative security update for Windows Server 2022, bringing OS build to 20348.3453 with DST, IIS, and Kerberos protections.

KB5055526: Windows Server 2022 Security Update (OS Build 20348.3453) - April 8, 2025 — navanem Microsoft KB cover
KB5055526 · Windows Server · Security Update

Summary

This is the April 8, 2025 cumulative security update for Windows Server 2022, advancing the OS build to 20348.3453. Released on April 8, 2025, it is a mandatory monthly security update that addresses DST changes, an OS security hardening measure, and a Kerberos authentication vulnerability. See the Microsoft Support page for full details.

Highlights

  • Daylight Saving Time update for Chile's Aysen region to reflect the government's 2025 DST change order.
  • A new %systemdrive%\inetpub folder is created on all devices after installing this update, as part of OS security hardening tied to CVE-2025-21204 - do not delete it.
  • Kerberos authentication gains new default protections against a vulnerability involving certificate authorities in the Windows root store but absent from the NTAuth store, per CVE-2025-26647.

Improvements and fixes

  • Daylight Saving Time (DST): The update adds DST rule support for Chile's Aysen region in line with a government order taking effect in 2025.
  • OS Security (CVE-2025-21204): After this update installs, Windows automatically creates a %systemdrive%\inetpub folder on the device. This folder must not be deleted, even when Internet Information Services (IIS) is not enabled. No action is required from IT admins or end users - the folder is part of a protection increase built into the update.
  • Kerberos Authentication (CVE-2025-26647): Default behavior is changed to add protections against a vulnerability that occurs when a certificate authority exists in the Windows root store but is absent from the NTAuth store. Administrators should be aware that this change, which is enabled by default, may generate Event ID 45 on domain controllers. Microsoft's KB5057784 has further guidance.
  • Servicing stack (KB5055668, build 20348.3440): A bundled servicing stack update improves the reliability and quality of the component responsible for installing Windows updates.

Known issues

Citrix Session Recording Agent blocks update installation

Symptom: Devices with Citrix Session Recording Agent (SRA) version 2411 (released December 2024) may fail to complete installation of the January 2025 Windows security update. The update appears to download and apply correctly, but on restart the device displays a message similar to "Something didn't go as planned. No need to worry - undoing changes" and reverts to the previously installed Windows updates. Home users are not expected to be affected.

Workaround: This issue is resolved in Citrix Session Recording Agent version 2503, released April 28, 2025, and later versions. Refer to Citrix documentation titled "Microsoft's January Security Update Fails/Reverts on a machine with 2411 Session Recording Agent" for details.

System Guard Runtime Monitor Broker service logs Event 7023

Symptom: On devices running Windows updates released January 14, 2025, or later, Windows Event Viewer may show Event 7023 under Windows Logs > System, with text similar to "The System Guard Runtime Monitor Broker service terminated with the following error: %%3489660935". The error is silent - it does not appear as a dialog or notification. SgrmBroker.exe was originally created for Microsoft Defender but no longer plays any role in its operation. No impact to performance, functionality, or device security level results from this issue. Administrators should not manually start, reconfigure, uninstall, or remove this service or its components, as future updates will adjust the relevant components.

Workaround: This issue is addressed in KB5055526 (this update).

Active Directory Group Policy audit logon events show incorrectly as disabled

Symptom: In the Local Group Policy Editor or Local Security Policy, the "Audit logon events" policy under Audit Logon/Logoff events may display a Security Setting of "No auditing" even when auditing is enabled and functioning correctly. This is a reporting inconsistency - logon events may still be audited as expected on the device. Home users are unlikely to encounter this issue since logon auditing is typically an enterprise requirement.

Workaround: This issue was resolved by the Windows update released April 11, 2025 (KB5058920). Installing that update is recommended to keep devices current.

How to get this update

Microsoft bundles the servicing stack update (KB5055668) together with this cumulative update, so no separate SSU installation is required. Before servicing an offline OS image, confirm that the image already includes KB5030216 (released September 12, 2023) or a later LCU. That update sets the minimum SSU version (20348.1960) needed to avoid error 0x800f0823 during installation.

This update is available through the following channels:

  • Windows Update / Microsoft Update: Downloads and installs automatically.
  • Windows Update for Business: Deploys automatically in line with configured policies.
  • Microsoft Update Catalog: A standalone package is available for manual download.
  • Windows Server Update Services (WSUS): Syncs automatically when Products and Classifications are set to Product: "Microsoft Server operating system-21H2" and Classification: "Security Updates".

To remove only the LCU after installation, use the DISM /online /remove-package command with the LCU package name as the argument. Running wusa.exe /uninstall against the combined package will not work because the SSU is included and cannot be removed after installation.

Frequently asked questions

Why is a new inetpub folder appearing on servers where IIS is not installed?

This is intentional behavior introduced by this update as part of the security hardening changes tied to CVE-2025-21204. Windows creates the %systemdrive%\inetpub folder regardless of whether IIS is enabled. Microsoft explicitly states the folder must not be deleted, and no action is required from IT admins or end users.

Will the Kerberos change cause problems in my Active Directory environment?

It may generate Event ID 45 on domain controllers in environments where a certificate authority exists in the Windows root store but is absent from the NTAuth store. This protection is enabled by default starting with this update. Microsoft's KB5057784 and the CVE-2025-26647 advisory provide additional guidance for evaluating the impact on your PKI configuration.

Is the SgrmBroker.exe Event 7023 error something I need to fix manually?

No. Microsoft states the error is silent, causes no performance or functionality impact, and does not reduce device security. Admins should not manually start, reconfigure, or remove the SgrmBroker.exe service or its components. Future Windows updates will handle the necessary adjustments automatically.

How do I confirm whether the Citrix SRA issue affects my environment?

Check whether any servers or managed devices are running Citrix Session Recording Agent version 2411, which was released in December 2024. If so, upgrade to version 2503 or later - released April 28, 2025 - before attempting to apply January 2025 or later Windows security updates. Microsoft notes this issue affects a limited number of organizations.

#windows-server-2022#security-update#kerberos#Active Directory#cumulative-update#patch-tuesday#iis

Related topics