NAVANEM
Security updateOS build 22621.5472 and 22631.5472

KB5060999: Windows 11 22H2 and 23H2 Cumulative Update - June 10, 2025

June 10, 2025 security update for Windows 11 22H2 and 23H2, delivering OS builds 22621.5472 and 22631.5472 with a graphics Remote Desktop fix.

KB5060999: Windows 11 22H2 and 23H2 Cumulative Update - June 10, 2025 — navanem Microsoft KB cover
KB5060999 · Windows 11 · Security Update

Summary

This is the June 10, 2025 monthly security cumulative update for Windows 11 versions 22H2 and 23H2, tracked as KB5060999. It produces OS builds 22621.5472 and 22631.5472 and is available through Windows Update, Windows Update for Business, WSUS, and the Microsoft Update Catalog. See the Microsoft Support page for the full official details.

Highlights

  • This update addresses security issues for the Windows operating system.

Improvements and fixes

  • Windows 11 version 23H2: This release carries all improvements present in Windows 11 version 22H2. No additional issues are documented for the 23H2 build specifically. Admins who have not yet moved to 23H2 should use KB5027397 as the enablement package.
  • Windows 11 version 22H2 - Graphics/Remote Desktop fix: Resolves a graphics support problem that stopped some users from connecting successfully via Remote Desktop. Affected users saw errors such as "The Remote Desktop Services session has ended" or "A remote desktop connection cannot be established." This fix was originally part of the May 27, 2025 preview update KB5058502.
  • Servicing stack update (KB5058546): A servicing stack update targeting builds 22621.5412 and 22631.5412 is bundled with this release. It improves the component responsible for installing Windows updates, helping devices reliably receive and apply future updates.

Known issues

Blurry CJK text in Chromium-based browsers (Noto fonts)

Symptom: Users may see blurry or unclear Chinese, Japanese, or Korean (CJK) text when content is displayed at 96 DPI (100% scaling) in Chromium-based browsers such as Microsoft Edge and Google Chrome. The March 2025 Preview Update introduced Noto fonts as CJK fallback fonts in collaboration with Google. The visual degradation occurs because limited pixel density at 96 DPI reduces the clarity and alignment of CJK characters. Increasing display scaling improves rendering clarity.

Workaround: Microsoft has shared its findings and potential solutions with Google for further discussion. Users can also report issues with Noto CJK fonts directly through the official Google Noto Fonts GitHub repository.

Update delivery delays under quality update deferral policies

Symptom: Some devices managed by IT admins using quality update (QU) deferral policies may receive the June 2025 security update later than expected. Although the update released on June 10, 2025, its update metadata timestamp reflects June 20, 2025. Devices with configured deferral periods calculate their wait window from the metadata date, not the actual release date, causing later-than-intended delivery.

Workaround: Admins have two options to accelerate deployment. First, if the organization uses Windows Autopatch, create an expedite policy to bypass deferral settings and push the update immediately. Second, adjust deployment rings or deferral configurations to shorten the delay window for affected devices. Microsoft confirms it will not change the metadata timestamp from June 20, 2025, and this workaround is the final resolution provided for the issue. The delay affects only timing and does not affect the quality or applicability of the update.

How to get this update

Microsoft combines the servicing stack update (SSU) for your OS version with the latest cumulative update (LCU) in a single package. The SSU included here is KB5058546 (builds 22621.5412 and 22631.5412).

  • Windows Update and Microsoft Update: The update downloads and installs automatically.
  • Windows Update for Business: Deploys automatically in line with configured policies.
  • Microsoft Update Catalog: Download the standalone package directly from the catalog.
  • WSUS: The update syncs automatically when Products is set to "Windows 11" and Classification is set to "Security Updates."

If you need to remove only the LCU after installation, use the DISM /Remove-Package command with the LCU package name. Running wusa.exe /uninstall against the combined package will not work because the SSU is included and cannot be removed once installed. Use DISM /online /get-packages to find the correct package name.

Note that Windows updates delivered through these channels do not include Microsoft Store application updates, which must be handled separately through the Microsoft Store or Configuration Manager.

Frequently asked questions

Does this update apply to both Windows 11 22H2 and 23H2?

Yes. KB5060999 covers both Windows 11 version 22H2 (Enterprise and Education) and Windows 11 version 23H2 (all editions), resulting in OS builds 22621.5472 and 22631.5472 respectively. Admins upgrading devices to 23H2 should use the enablement package KB5027397 before applying this cumulative update.

Is a servicing stack update required before installing this update?

Microsoft bundles the required servicing stack update - KB5058546 - directly into the cumulative update package for this release. No separate SSU installation step is needed. However, admins should be aware that the SSU portion cannot be uninstalled once the combined package is applied.

Why are devices with deferral policies receiving this update late?

The update's metadata timestamp is set to June 20, 2025, even though it released on June 10, 2025. Deferral periods are calculated from the metadata date, pushing delivery beyond what admins may expect. Microsoft will not correct the metadata value; the recommended resolution is to create an expedite policy in Windows Autopatch or to adjust deferral ring configurations.

What should admins do about the blurry CJK text in Edge and Chrome?

The blurry CJK text issue at 96 DPI (100% scaling) stems from the Noto fonts introduced in March 2025 and the limited pixel density at that scaling level. No in-product fix is currently available for this update. The immediate mitigation is to increase display scaling, which improves rendering clarity. Microsoft is working with Google on a broader resolution.

#windows-11#cumulative-update#security-update#Remote Desktop#cjk-fonts#wsus#patch-tuesday

Related topics