NAVANEM
Security updateOS build 26100.4652

KB5062553: Windows 11 Version 24H2 Security Update (OS Build 26100.4652) - July 2025

July 8, 2025 security update for Windows 11 version 24H2, lifting the OS to build 26100.4652. Fixes graphics sync and notification sound issues.

KB5062553: Windows 11 Version 24H2 Security Update (OS Build 26100.4652) - July 2025 — navanem Microsoft KB cover
KB5062553 · Windows 11 · Security Update

Summary

KB5062553 is the July 8, 2025 monthly security cumulative update for Windows 11 version 24H2. It raises the OS to build 26100.4652, addresses security vulnerabilities, and delivers two targeted quality fixes carried forward from the June 2025 non-security release. Deployment is available through Windows Update, Windows Update for Business, and the Microsoft Update Catalog. See Microsoft Support for the full official details.

Highlights

  • This update addresses security issues for the Windows operating system.

Improvements and fixes

  • Graphics - cursor sync fix: When the June 2025 non-security update (KB5060829) was installed, game content could fall out of sync with the cursor after using ALT + Tab to switch away from and back to certain full-screen exclusive games whose resolution did not match the desktop resolution. This update resolves that problem.
  • Multimedia - notification sounds fix: An issue prevented notification sounds from playing, including sounds for on-screen alerts, volume adjustments, and sign-in. This update corrects that behavior.
  • AI component updates: This release refreshes three AI components - Image Search (1.2506.707.0), Content Extraction (1.2506.711.0), and Semantic Analysis (1.2506.707.0). These components apply only to Copilot+ PCs and will not install on standard Windows PCs or Windows Server.
  • Bundled servicing stack update: The package includes servicing stack update KB5063666 (build 26100.4651), which improves the reliability of the component responsible for installing Windows updates.

Known issues

Azure VM with Trusted Launch disabled

Symptom: A small subset of Generation 2 Azure Virtual Machines with Trusted Launch disabled, and Virtualization-Based Security (VBS) enforced via registry key, may be unable to boot after installing this update. To check whether a VM could be affected, confirm it was created as "Standard" and verify that VBS is running by opening System Information (msinfo32.exe) - look for "Virtualization-based security" showing as running and confirm the Hyper-V role is not installed in the VM.

Workaround: This issue is addressed in KB5064489.

Microsoft Changjie Input Method Editor

Symptom: After installing this update, users of the Microsoft Changjie IME for Traditional Chinese may experience one or more of the following problems: inability to form or select words after typing the full composition (associate phrase window); the spacebar or blank key not responding; incorrect or distorted word outputs; and the conversion candidate window failing to display properly.

Workaround: This issue is addressed in KB5062660.

How to get this update

Microsoft bundles the latest servicing stack update (SSU) with the latest cumulative update (LCU) in a single package, so no separate SSU installation step is required before applying KB5062553.

  • Windows Update / Microsoft Update: The update downloads and installs automatically on eligible devices.
  • Windows Update for Business: The update deploys automatically in accordance with configured policies.
  • Microsoft Update Catalog: Download the standalone package manually. Two MSU files are available. You can install them together using DISM.exe by placing all files in one folder and pointing the /PackagePath argument at that folder, or you can install them individually in order - first the prerequisite KB5043080 MSU, then the KB5062553 MSU. DISM and PowerShell (Add-WindowsPackage) commands are both supported.
  • Windows Server Update Services (WSUS): Configure Products as "Windows 11" and Classifications as "Security Updates" to sync this update automatically.

To remove only the LCU after installation, use DISM /online /remove-package with the LCU package name. Running wusa.exe /uninstall against the combined package will not work because the SSU is embedded and cannot be removed after installation.

Frequently asked questions

Does this update apply to Windows Server or standard Windows PCs without Copilot+ hardware?

The core security and quality fixes apply to all Windows 11 version 24H2 devices. However, the AI component updates bundled in this release - Image Search, Content Extraction, and Semantic Analysis - are specific to Copilot+ PCs and will not install on standard Windows PCs or Windows Server machines.

What should IT admins do about the Secure Boot certificate expiration warning?

Secure Boot certificates on most Windows devices are set to expire starting June 2026. Microsoft has been pushing updated certificates to consumer and non-managed devices for several months. Managed environments should follow the guidance in the Secure Boot Playbook for Windows clients and Windows Server. Devices that have not yet received new certificates will continue to start and operate normally in the meantime.

Can I deploy this update to Azure Generation 2 VMs with Trusted Launch disabled?

Use caution. A small subset of Generation 2 Azure VMs with Trusted Launch disabled and VBS enforced via registry key may fail to boot after applying this update. Verify your VM configuration before deploying, and apply KB5064489 which addresses the issue. Check System Information (msinfo32.exe) to confirm VBS status before patching.

How do I verify which files are included in this update?

Microsoft publishes a separate file information download for both the cumulative update (KB5062553) and the bundled servicing stack update (KB5063666, version 26100.4651). Download those file lists from the Microsoft Support page to audit exactly which files the package modifies before deploying it in your environment.

#windows-11#24h2#security-update#cumulative-update#graphics#multimedia#secure-boot

Related topics