KB5062560: Windows 10 v1607 and Server 2016 Security Update - OS Build 14393.8246
July 8, 2025 security update for Windows 10 v1607 and Windows Server 2016, delivering OS build 14393.8246 with security hardening and quality fixes.

Summary
This is a security update for Windows 10, version 1607 and Windows Server 2016, producing OS build 14393.8246. Released on July 8, 2025, it delivers security hardening improvements and quality fixes that build on the prior cumulative update from June 10, 2025. Source: Microsoft Support.
Improvements and fixes
- For Windows 10 IoT Enterprise LTSB 2016: miscellaneous security improvements to internal Windows OS functionality are included. No specific issues are separately documented for this component in this release.
- For Hyper-V Server 2016: a fix is included for a bug where the DHCP Server service could intermittently stop responding, disrupting IP address renewal for clients.
- For Hyper-V Server 2016: a security hardening change tightens access checks for a set of remote procedure call (RPC) requests made through the Microsoft RPC Netlogon protocol. After installation, Active Directory domain controllers will no longer allow anonymous clients to invoke certain RPC requests via the Netlogon RPC server. These requests are typically related to domain controller location. Certain file and print service software, including Samba, may be affected; administrators using Samba are directed to review the Samba release notes.
Known issues
Microsoft Changjie Input Method Editor
Symptom: After installing this update, users of the Microsoft Changjie IME for Traditional Chinese may encounter several problems. Reported symptoms include inability to form or select words after typing the full composition in the associate phrase window, the spacebar or blank key not responding, incorrect or distorted word outputs, and the conversion candidate window failing to display properly.
Workaround: This issue is resolved by Windows updates released on and after August 12, 2025 (KB5063871). Microsoft recommends installing the latest available update, which contains this resolution along with other improvements.
How to get this update
Before installing KB5062560, any device running Windows 10, version 1607 must have the latest Servicing Stack Update (SSU) installed. Microsoft notes that without the latest SSU, this update will not be offered. The required SSU is KB5062799.
- Windows Update and Microsoft Update: The SSU (KB5062799) is offered automatically. Once the SSU is installed, KB5062560 is then downloaded and installed automatically.
- Windows Update for Business: The SSU is offered automatically in line with configured policies, after which this cumulative update follows.
- Microsoft Update Catalog: Administrators must manually download and install SSU KB5062799 first, then obtain the standalone package for KB5062560 from the Microsoft Update Catalog website.
- Windows Server Update Services (WSUS): Administrators must approve both SSU KB5062799 and this update KB5062560 separately. To sync automatically, configure Products as Windows 10 and Classification as Security Updates.
A CSV file listing all files included in this update is available to download from the Microsoft Support page.
Frequently asked questions
Is the Servicing Stack Update mandatory before installing this update?
Yes. Microsoft states that any Windows 10, version 1607 cumulative update released on or after January 14, 2025 requires the latest SSU to be installed first. Without SSU KB5062799 present, this update will not be offered to the device at all. Install the SSU as soon as possible to reduce security exposure.
Which products does this update apply to?
This update applies to Windows 10, version 1607, all editions, and Windows Server 2016, all editions. Specific fix applicability within the update varies by product - the DHCP Server fix and Netlogon hardening apply to Hyper-V Server 2016, while the internal OS security improvements target Windows 10 IoT Enterprise LTSB 2016.
Does this update affect Samba or third-party authentication services?
Possibly. The Microsoft RPC Netlogon protocol hardening introduced in this update causes domain controllers to reject certain anonymous RPC requests related to domain controller location. Microsoft specifically notes that Samba and certain file and print service software can be affected. Administrators using Samba should review the Samba release notes before deploying.
What are the end-of-support dates for the products covered by this update?
Support for Windows 10 ended on October 14, 2025. Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise 2016 LTSB reach end of support on October 13, 2026. Windows Server 2016 reaches end of support on January 12, 2027. After these dates, Microsoft will no longer provide free updates, technical assistance, or security fixes through Windows Update.







