NAVANEM
Security updateOS build 20348.3989

August 12, 2025 Hotpatch KB5063812 for Windows Server 2022 Datacenter: Azure Edition (OS Build 20348.3989)

KB5063812 is a security hotpatch for Windows Server 2022 Datacenter: Azure Edition, releasing OS Build 20348.3989 on August 12, 2025.

KB5063812: August 12, 2025 Hotpatch KB5063812 for Windows Server 2022 Datacenter: Azure Edition (OS Build 20348.3989) — navanem Microsoft KB cover
KB5063812 · Windows Server · Security Update

Summary

KB5063812 is a security hotpatch update for Windows Server 2022 Datacenter: Azure Edition, released on August 12, 2025, bringing the OS to build 20348.3989. It delivers miscellaneous security improvements to internal OS functionality with no additional documented issues. The update is distributed through Windows Update, Microsoft Update Catalog, and WSUS. See Microsoft Support for the official page.

Improvements and fixes

  • This update introduces miscellaneous security improvements to internal OS functionality. Microsoft notes no additional issues are documented in this release.

Known issues

Microsoft lists no known issues for this update at the time of writing.

How to get this update

Before installing, note that Microsoft now combines the latest servicing stack update (SSU) with the hotpatch update package. If you are using Windows Update or Windows Server Update Services (WSUS), the latest SSU installs automatically alongside this update. The accompanying SSU is KB5062793, version 20348.3920.

Installation channels:

  • Windows Update / Microsoft Update - The update downloads and installs automatically.
  • Windows Update Catalog - Available for manual download and deployment.
  • Windows Server Update Services (WSUS) - The update syncs automatically when Products and Classifications are configured as follows: Product set to "Server 2022 Hotpatch Category" and Classification set to "Security Updates".

File information: To review the files included in this update, download the file information for cumulative update KB5063812. For the servicing stack update file list, download the file information for SSU KB5062793, version 20348.3920.

Important - Windows Secure Boot certificate expiration: Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. Microsoft has been updating these certificates on consumer and non-managed business devices. Devices that have not yet received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. IT administrators should follow the guidance in the Secure Boot Playbook for Windows clients and Windows Server.

Frequently asked questions

What is a hotpatch update, and how does it differ from a standard cumulative update?

A hotpatch update applies security fixes to in-memory code on running processes, so a system restart is not required at installation time. This contrasts with a standard cumulative update, which typically patches files on disk and requires a reboot to take effect. Hotpatch is available specifically for Windows Server 2022 Datacenter: Azure Edition.

Does KB5063812 include a servicing stack update?

Yes. Microsoft now bundles the latest SSU with the hotpatch package. If you deploy via Windows Update or WSUS, SSU KB5062793 (version 20348.3920) installs alongside the security update automatically. No separate SSU download step is required when using those channels.

Which WSUS product and classification settings are needed to receive this update?

In your WSUS configuration, set the Product to "Server 2022 Hotpatch Category" and the Classification to "Security Updates". Once those settings are in place, the update syncs to your WSUS server and becomes available for approval and deployment to eligible systems.

What should IT administrators know about the upcoming Secure Boot certificate expiration?

Secure Boot certificates on most Windows devices are set to expire beginning in June 2026. Microsoft is rolling out updated certificates through Windows updates over the coming months. Administrators managing non-consumer or enterprise environments should consult the Secure Boot Playbook for Windows Server to verify certificate status and ensure managed devices receive the updated certificates before the expiration window.

#hotpatch#windows-server-2022#azure-edition#security-update#servicing-stack#kb5063812