KB5058405: Windows 11 Security Update for Versions 22H2 and 23H2 (May 13, 2025)
May 13, 2025 security update for Windows 11 versions 22H2 and 23H2, delivering OS builds 22621.5335 and 22631.5335 with SBAT improvements and a WSUS upgrade fix.

Summary
This is the Microsoft Support page for KB5058405, a security update for Windows 11 versions 22H2 and 23H2. It delivers OS builds 22621.5335 and 22631.5335, released on May 13, 2025. The update addresses security issues for the Windows operating system and includes quality improvements.
Highlights
- This update addresses security issues for the Windows operating system.
Improvements and fixes
The following changes apply specifically to Windows 11, version 22H2 (build 22621.5335). Version 23H2 includes all of these same improvements, with no additional documented changes for that release.
- Secure Boot Advanced Targeting (SBAT) and Linux EFI: The update applies improvements to SBAT for the detection of Linux systems.
- Windows Update: Fixes an issue where devices could not update to Windows 11, version 24H2 through WSUS. The download would fail to start or complete, producing error code 0x80240069 and log entries showing "Service has unexpectedly stopped".
This update also bundles quality improvements that were part of update KB5055629, released April 22, 2025. A companion servicing stack update, KB5058528 (versions 22621.5334 and 22631.5334), is included to improve the reliability of the component that installs Windows updates.
Known issues
Blurry CJK text in Chromium-based browsers (Noto fonts)
Symptom: Some users report blurry or unclear CJK (Chinese, Japanese, Korean) text when content is displayed at 96 DPI (100% scaling) in Chromium-based browsers such as Microsoft Edge and Google Chrome. The March 2025 Preview Update introduced Noto fonts for CJK languages as fallbacks, in collaboration with Google, to improve text rendering when websites or apps do not specify appropriate fonts. The blurriness is due to limited pixel density at 96 DPI, which can reduce the clarity and alignment of CJK characters. Increasing display scaling improves clarity.
Workaround: Microsoft has shared its findings on the blurry text issue at 96 DPI, along with potential solutions, with Google for further discussion. Users can also report issues related to Noto CJK fonts through the official Google Noto Fonts GitHub repository.
Recovery error 0xc0000098 (ACPI.sys) after update installation
Symptom: While installing the May 2025 Windows security update, some devices may encounter the following recovery error: "Your PC/device needs to be repaired. The operating system couldn't be loaded because a required file is missing or contains errors. File: ACPI.sys. Error code: 0xc0000098." This issue is observed primarily on devices running in virtual environments, including Azure Virtual Machines, Azure Virtual Desktop, and on-premises virtual machines hosted on Citrix or Hyper-V. There are also reports of the same error occurring with a different file name. Home users on Windows Home or Pro editions are unlikely to face this issue.
Workaround: This issue is addressed in KB5062170. If KB5058405 has not yet been deployed in an IT environment that includes virtual desktop infrastructure, Microsoft recommends applying the out-of-band update KB5062170 instead.
For devices already affected and unable to start Windows, the following recovery steps apply:
- Recovery-enabled devices: Access the Windows Recovery Environment, then restart Windows.
- Non-Recovery-enabled devices: Mount the virtual hard disk (VHD) from a remote device, attach the VHD to another VM or device as a data disk, then return it to the affected VM and restart Windows in normal mode. This reverts Windows to the last successfully installed update.
Azure customers who have already applied the update and are experiencing issues should see the self-help repair steps outlined in the Microsoft documentation for repairing a Windows VM using Azure Virtual Machine repair commands. After recovery, install KB5062170 via the Microsoft Update Catalog.
How to get this update
Microsoft combines the latest servicing stack update (SSU) with the latest cumulative update (LCU) into a single package for this release. The update is available through the following channels:
- Windows Update and Microsoft Update: The update downloads and installs automatically.
- Windows Update for Business: The update downloads and installs automatically in accordance with configured policies.
- Microsoft Update Catalog: A standalone package is available for manual download.
- Windows Server Update Services (WSUS): The update syncs automatically when Products and Classifications are configured with Product set to Windows 11 and Classification set to Security Updates.
To remove the LCU after installing the combined SSU and LCU package, use the DISM /Remove-Package command with the LCU package name as the argument. Running wusa.exe with the /uninstall switch on the combined package will not work, because the package contains the SSU, which cannot be removed from the system after installation.
Frequently asked questions
Does this update apply to both Windows 11 22H2 and 23H2?
Yes. KB5058405 covers both Windows 11 version 22H2 (Enterprise and Education) and Windows 11 version 23H2 (all editions). Both reach the same resulting build level: 22621.5335 for 22H2 and 22631.5335 for 23H2. The 23H2 build includes all improvements made to 22H2 with no additional documented changes.
Is the servicing stack update bundled in this package, or do I need to install it separately?
Microsoft combines the servicing stack update (KB5058528, versions 22621.5334 and 22631.5334) with this cumulative update into a single package. No separate SSU installation step is required before deploying KB5058405.
What should I do if virtual machines in my environment hit the 0xc0000098 recovery error after applying this update?
If you have not yet deployed KB5058405 in a virtual desktop infrastructure environment, apply the out-of-band update KB5062170 instead. If devices are already affected and cannot start Windows, follow the recovery steps outlined in the known issues section, then install KB5062170 from the Microsoft Update Catalog once the device is operational.
Will this update also install Microsoft Store app updates?
No. Windows updates delivered through KB5058405 do not install Microsoft Store application updates. Enterprise users should manage Store app updates through Microsoft Store apps - Configuration Manager, and consumer users should use the Get updates for apps and games in Microsoft Store option.









