NAVANEM
Security updateOS build 20348.3807

KB5060526: Windows Server 2022 Security Update - OS Build 20348.3807 (June 2025)

KB5060526 is the June 10, 2025 cumulative security update for Windows Server 2022, bringing it to OS build 20348.3807 with graphics, memory, Settings, and Windows Hello fixes.

KB5060526: Windows Server 2022 Security Update - OS Build 20348.3807 (June 2025) — navanem Microsoft KB cover
KB5060526 · Windows Server · Security Update

Summary

KB5060526 is the cumulative security update for Windows Server 2022, releasing on June 10, 2025 and bringing the OS to build 20348.3807. It addresses graphics rendering problems, an Input Service memory leak, a Settings app restart loop, and a Windows Hello for Business sign-in failure. See Microsoft Support for the official page.

Highlights

  • Fixed character-width rendering and font preview display issues in the Graphics subsystem.
  • Corrected display of GB18030-2022 extended Chinese characters.
  • Resolved an Input Service memory leak affecting multi-user, multilingual, and Remote Desktop environments.
  • Fixed a Settings app policy bug that caused repeated restarts and automatic entry into repair mode.
  • Fixed Windows Hello for Business Key Trust sign-in failures caused by self-signed certificates.

Improvements and fixes

  • Graphics - character width: Some characters were appearing wider than standard characters, and the sample paragraph in the font preview section was not rendering correctly. This update corrects that behavior.
  • Graphics - GB18030-2022: Certain extended Chinese characters defined in the GB18030-2022 standard were not displaying correctly. This update restores proper rendering for that character set.
  • Memory leak - Input Service: The Input Service was accumulating memory over time, which could degrade performance on systems running multiple users, multiple languages, or Remote Desktop sessions. This update eliminates that leak.
  • Settings app - repair mode loop: Enabling the "Prohibit Access to Control Panel and PC Settings" Group Policy could cause the system to restart repeatedly and enter repair mode automatically. This update prevents that failure path.
  • Windows Hello for Business - Key Trust: Users were unable to sign in with self-signed certificates when the deployment used the Key Trust model. This update restores sign-in capability for that configuration.

This update also bundles servicing stack update KB5058531 (SSU version 20348.3691), which improves the reliability of the component responsible for installing Windows updates.

Known issues

DHCP Server service stops responding

Symptom: After installing this security update, the DHCP Server service may intermittently stop responding. When this occurs, clients are unable to renew their IP addresses, potentially causing network connectivity problems across the environment.

Workaround: This issue was resolved by Windows updates released on and after July 8, 2025 (KB5062572). Microsoft recommends installing the latest available update for your device, as it contains this resolution along with other important improvements.

How to get this update

Before installing, note that Microsoft now combines the latest SSU with the latest cumulative update (LCU) in a single package. For offline OS image servicing, the image must already include KB5030216 (September 12, 2023) or a later LCU. Without it, install that LCU on your offline media first to bring the SSU to version 20348.1960, the minimum required to avoid error 0x800f0823 (CBS_E_NEW_SERVICING_STACK_REQUIRED).

Once prerequisites are met, the update is available through the following channels:

  • Windows Update / Microsoft Update: Downloads and installs automatically.
  • Windows Update for Business: Deploys automatically in accordance with your configured policies.
  • Microsoft Update Catalog: Download the standalone package directly from the Catalog website.
  • Windows Server Update Services (WSUS): Syncs automatically when Products and Classifications are set to Product: Microsoft Server operating system-21H2 and Classification: Security Updates.

Note that the combined package includes updates for AI components, but those components apply only to Windows Copilot+ PCs and will not install on standard Windows PCs or Windows Server.

To remove the LCU after installation, use the DISM /online /remove-package command with the LCU package name as the argument. Running wusa.exe /uninstall against the combined package will not work because the SSU is embedded and cannot be removed after installation.

Frequently asked questions

Does this update replace a separate servicing stack update?

Yes. Microsoft now ships the servicing stack update and the cumulative update together in one package. KB5060526 includes SSU KB5058531 at version 20348.3691. You do not need to download a separate SSU before applying this update on a fully up-to-date system.

What should I do if the DHCP Server service stops responding after installing this update?

Microsoft confirmed this as a known issue and resolved it in updates released on and after July 8, 2025, starting with KB5062572. Install that update or any later cumulative update for Windows Server 2022 to resolve the DHCP service instability introduced by KB5060526.

Is a prerequisite required before deploying this update to offline images?

Yes. Offline OS images must include KB5030216 (September 12, 2023) or a later LCU before you apply KB5060526. Skipping this step can result in error 0x800f0823. Online systems that are kept current through Windows Update or WSUS are not affected by this requirement.

Where can I find detailed file information for this update?

Microsoft provides separate file information downloads for the cumulative update (KB5060526) and the bundled servicing stack update (KB5058531, version 20348.3691). Links to both file lists are available on the official support page for this update.

#windows-server-2022#security-update#cumulative-update#windows-hello#dhcp#graphics#memory-leak

Related topics