April 8, 2025 - KB5055528 (OS Builds 22621.5189 and 22631.5189)
April 8, 2025 security update for Windows 11 versions 22H2 and 23H2, bringing OS builds to 22621.5189 and 22631.5189 with security fixes and DST changes.

Summary
KB5055528 is the April 8, 2025 monthly security update for Windows 11 versions 22H2 and 23H2, advancing both OS builds to 22621.5189 and 22631.5189. Released on April 8, 2025, it addresses security vulnerabilities, includes a Daylight Saving Time fix for Chile, and changes Windows Hello facial recognition behavior. Full details are on the Microsoft Support page.
Highlights
- Daylight Saving Time (DST): Adds support for the Chilean government DST change order for 2025, specifically for the Aysen region. More information is available on the Daylight Saving Time and Time Zone Blog.
- OS Security - inetpub folder: After installing this update or any later Windows update, a new
%systemdrive%\inetpubfolder is created on the device. This folder must not be deleted, regardless of whether Internet Information Services (IIS) is enabled. This is a deliberate protection change tied to CVE-2025-21204 and requires no action from IT admins or end users. - Windows Hello facial recognition: For enhanced security, Windows Hello facial recognition now requires color cameras to detect a visible face when signing in. This change is linked to CVE-2025-26644.
Improvements and fixes
- For Windows 11, version 23H2: This security update includes all improvements present in Windows 11, version 22H2. No additional issues are documented for this release. Updating to version 23H2 requires KB5027397.
- For Windows 11, version 22H2: The update incorporates improvements previously delivered in KB5053657, released March 25, 2025. It applies miscellaneous security improvements to internal OS functionality. No additional issues beyond security changes are documented for this release.
- A servicing stack update (KB5053665) - versions 22621.5120 and 22631.5120 - is bundled with this release. It delivers quality improvements to the servicing stack component responsible for installing Windows updates, helping ensure devices can reliably receive and apply future updates.
Known issues
Citrix Session Recording Agent blocks update installation
Symptom: Devices with certain Citrix components installed - specifically Citrix Session Recording Agent (SRA) version 2411, released December 2024 - may fail to complete installation of the January 2025 Windows security update. The update may initially download and apply correctly, but on restart the device shows an error similar to "Something didn't go as planned. No need to worry - undoing changes" and reverts to the previously installed update state. Home users are not expected to be affected.
Workaround: This issue is resolved in Citrix Session Recording Agent version 2503, released April 28, 2025, and later versions. Refer to Citrix documentation titled "Microsoft's January Security Update Fails/Reverts on a machine with 2411 Session Recording Agent" for details.
Active Directory Group Policy audit logon events display incorrectly
Symptom: Audit Logon/Logoff events configured in the local policy of Active Directory Group Policy may not appear as enabled in the Local Group Policy Editor or Local Security Policy, even when they are enabled and functioning correctly. The "Audit logon events" policy may show a Security Setting of "No auditing" despite logon events being properly audited. This is likely a reporting inconsistency and primarily affects enterprise environments.
Workaround: This issue was resolved by the Windows update released April 11, 2025 (KB5058919). Installing that update or a later update resolves the display inconsistency.
Windows 11 version 24H2 upgrade may not download via WSUS
Symptom: Devices that have installed the April 8, 2025 monthly security update (KB5055528) or a later update may be unable to upgrade to Windows 11, version 24H2 through Windows Server Update Services (WSUS). The download does not initiate or complete. The Windows Update log may show error code 0x80240069, and further log entries may include text similar to "Service has unexpectedly stopped." Home users are unlikely to encounter this issue, as WSUS is an enterprise feature.
Workaround: This issue is addressed in KB5058405, released May 13, 2025. Devices that have installed KB5058405 or a later update do not require a Known Issue Rollback (KIR) or special Group Policy. For devices running an update released before May 13, 2025, IT admins can deploy the special Group Policy via the downloadable MSI file "Windows 11 22H2 KB5055528 250426_03001 Known Issue Rollback.msi" (also applicable to Windows 11, version 23H2). The policy is located under Computer Configuration > Administrative Templates. See Microsoft's guidance on deploying a Known Issue Rollback for instructions.
Blurry CJK text in Chromium-based browsers (Noto fonts)
Symptom: Some users report blurry or unclear Chinese, Japanese, and Korean (CJK) text when displayed at 96 DPI (100% scaling) in Chromium-based browsers such as Microsoft Edge and Google Chrome. The March 2025 Preview Update introduced Noto fonts as CJK fallback fonts in collaboration with Google. The blurriness is due to limited pixel density at 96 DPI, which can reduce clarity and alignment of CJK characters. Increasing display scaling improves text rendering clarity.
Workaround: Microsoft has shared findings and potential solutions with Google for further discussion. Users can report issues related to Noto CJK fonts through the official Google Noto Fonts GitHub repository.
Windows Hello facial recognition sign-in change
Symptom: After installing this update, users may be unable to sign in using Windows Hello facial recognition in low-light conditions or when the camera lens is covered.
Workaround: This is an intentional design change for enhanced security, not a defect. See the Highlights section for full details regarding CVE-2025-26644.
How to get this update
Microsoft bundles the latest servicing stack update (SSU) with the latest cumulative update (LCU) in a single package. The SSU included here is KB5053665 (versions 22621.5120 and 22631.5120).
This update is available through the following channels:
- Windows Update and Microsoft Update: Downloads and installs automatically.
- Windows Update for Business: Deploys automatically in line with configured policies.
- Microsoft Update Catalog: The standalone package is available for manual download.
- Windows Server Update Services (WSUS): Syncs automatically when Products is set to "Windows 11" and Classification is set to "Security Updates."
To remove the LCU after installing the combined SSU and LCU package, use the DISM /online /remove-package command with the LCU package name as the argument. Running wusa.exe with the /uninstall switch will not work on the combined package because it contains the SSU, which cannot be removed after installation.
Frequently asked questions
Why was a new inetpub folder created on my device after this update?
Installing KB5055528 or any later Windows update creates a %systemdrive%\inetpub folder as part of security hardening measures tied to CVE-2025-21204. This behavior applies whether or not IIS is enabled on the device. The folder must not be deleted, and no action is required from IT admins or end users.
Does this update change how Windows Hello facial recognition works?
Yes. After installing this update, Windows Hello facial recognition requires a color camera to detect a visible face during sign-in, as a security enhancement linked to CVE-2025-26644. If users cannot sign in in low-light conditions or with a covered lens, this is the expected new behavior, not a malfunction.
We use WSUS to manage updates - are there any known problems with this release?
Yes. Devices that installed KB5055528 or a later update may be unable to upgrade to Windows 11, version 24H2 via WSUS, with error code 0x80240069 appearing in logs. The fix is included in KB5058405, released May 13, 2025. Admins on older updates can deploy a Known Issue Rollback Group Policy as a temporary measure.
Do we need to take any action regarding Citrix before deploying this update?
Organizations running Citrix Session Recording Agent version 2411 should upgrade to version 2503 or later before deploying this or the January 2025 security update. Version 2411 causes update installation to revert on restart. Upgrading the Citrix component first prevents the rollback behavior from occurring.









