NAVANEM
Security updateOS build 22621.5768 and 22631.5768

KB5063875: Windows 11 Security Update - OS Builds 22621.5768 and 22631.5768 (August 12, 2025)

August 12, 2025 cumulative security update for Windows 11 versions 22H2 and 23H2, delivering OS builds 22621.5768 and 22631.5768.

KB5063875: Windows 11 Security Update - OS Builds 22621.5768 and 22631.5768 (August 12, 2025) — navanem Microsoft KB cover
KB5063875 · Windows 11 · Security Update

Summary

This is the mandatory monthly security update for Windows 11 versions 22H2 (Enterprise and Education) and 23H2, released on Microsoft Support on August 12, 2025. It produces OS builds 22621.5768 and 22631.5768 and addresses security issues across the Windows operating system.

Highlights

  • This update addresses security issues for the Windows operating system.

Improvements and fixes

  • Windows 11, version 23H2: This build carries all improvements present in Windows 11, version 22H2. No additional issues are documented specifically for 23H2 in this release. Use KB5027397 to update a device to version 23H2 before applying this cumulative update.
  • Copilot key reliability (22H2): Resolved a problem that stopped users from restarting Copilot after pressing the Copilot key, and improved the key's overall reliability.
  • Cumulative quality content (22H2): This update also includes all fixes and quality improvements that shipped with KB5062663, released July 22, 2025. Devices that already have earlier updates installed will download only the new content in this package.

Known issues

Reset and recovery failure

Symptom: After installing KB5063875, attempts to reset or recover the device may fail. The failure can occur when a user initiates any of the following processes: System > Recovery > Reset my PC, System Recovery > Fix problems using Windows Update, or the RemoteWipe CSP.

Workaround: This issue is addressed in KB5066189.

Unexpected UAC prompt during MSI repair operations

Symptom: A security improvement introduced in this update enforces a User Account Control (UAC) prompt for administrator credentials when Windows Installer (MSI) repair and related operations are performed, addressing security vulnerability CVE-2025-50173. After installing the update, standard users may encounter a UAC prompt in the following scenarios:

  • Running MSI repair commands such as msiexec /fu.
  • Opening Autodesk applications - including some versions of AutoCAD, Civil 3D, and Inventor CAM - or installing an MSI file after signing into the app for the first time.
  • Installing applications that configure on a per-user basis.
  • Running Windows Installer during Active Setup.
  • Deploying packages through Microsoft Configuration Manager (ConfigMgr) that rely on user-specific advertising configurations.
  • Enabling Secure Desktop.

If a non-admin user runs an application that initiates an MSI repair operation without displaying a UI, the operation will fail with an error. For example, installing and running Office Professional Plus 2010 as a standard user will fail with Error 1730 during configuration.

Workaround: This issue is addressed in KB5065431.

How to get this update

Microsoft bundles the latest servicing stack update (SSU) for the operating system together with the latest cumulative update (LCU) in a single package. The SSU component for this release is KB5062686, covering versions 22621.5690 and 22631.5690.

This update is available through the following channels:

  • Windows Update and Microsoft Update: The update downloads and installs automatically.
  • Windows Update for Business: The update deploys automatically in accordance with configured policies.
  • Microsoft Update Catalog: Download the standalone package directly from the catalog.
  • Windows Server Update Services (WSUS): The update syncs automatically when Products is set to Windows 11 and Classification is set to Security Updates.

Removing the LCU: To remove only the LCU after installing the combined SSU and LCU package, use the DISM /Remove-Package command with the LCU package name as the argument. You can retrieve the package name with DISM /online /get-packages. Running wusa.exe with the /uninstall switch against the combined package will not work because the package contains the SSU, and the SSU cannot be removed after installation.

End-of-servicing notice: Starting June 26, 2025, Windows 11 version 22H2 (Enterprise and Education) no longer receives non-security preview updates. Monthly security updates continue through October 14, 2025, after which the version reaches end of servicing. Microsoft recommends upgrading to the latest version of Windows 11.

Frequently asked questions

Does this update apply to Windows 11 Home and Pro on version 22H2?

No. The page states that KB5063875 applies specifically to Windows 11 Enterprise and Education on version 22H2, and to all editions of Windows 11 version 23H2. Home and Pro users on 22H2 are not listed in the Applies To scope for this update.

Do I need to install the servicing stack update separately before applying this update?

No separate SSU installation step is required. Microsoft combines the latest SSU (KB5062686, versions 22621.5690 and 22631.5690) with the LCU in a single package, so both components install together when you apply KB5063875 through any of the supported channels.

What should I do if device reset or recovery fails after installing this update?

The page states that the reset and recovery failure is addressed in KB5066189. Administrators should deploy that update to affected devices. Until KB5066189 is installed, reset and recovery operations initiated through Reset my PC, Fix problems using Windows Update, or RemoteWipe CSP may not complete successfully.

Will the new UAC prompt for MSI repair operations affect software deployment through ConfigMgr?

Yes, potentially. The page notes that packages deployed through ConfigMgr that rely on user-specific advertising configurations may trigger unexpected UAC prompts for standard users. The fix for this behavior is included in KB5065431, which administrators should evaluate and deploy to affected environments as soon as possible.

#windows-11#security-update#cumulative-update#22h2#23h2#copilot#servicing-stack

Related topics