KB5063878: Windows 11 24H2 Security Update (OS Build 26100.4946) - August 12, 2025
August 12, 2025 cumulative security update for Windows 11 version 24H2, bringing OS to build 26100.4946 with authentication fixes and AI component updates.

Summary
This is the August 12, 2025 cumulative security update for Windows 11 version 24H2, advancing the OS to build 26100.4946. Released on August 12, 2025, it addresses security vulnerabilities, fixes a sign-in delay on new devices, and updates several AI components. It also bundles servicing stack update KB5065381 (build 26100.4933). Source: Microsoft Support
Highlights
- This update addresses security issues for the Windows operating system.
Improvements and fixes
- Authentication: Resolves a problem that caused sign-in delays on new devices. The delays were traced to certain preinstalled packages slowing down the authentication process.
- Security vulnerabilities: Contains fixes for issues documented in the August 2025 Security Updates, detailed in the Security Update Guide.
- Cumulative quality improvements: Incorporates all fixes and quality improvements previously delivered in KB5062660, released July 22, 2025.
- AI component updates: Updates four AI components - Image Search, Content Extraction, Semantic Analysis, and Settings Model - all to version 1.2507.797.0. These components apply only to Windows Copilot+ PCs and will not install on standard Windows PCs or Windows Server.
- Servicing stack update: Includes KB5065381 (version 26100.4933), which improves the reliability and quality of the component responsible for installing Windows updates.
Note on Secure Boot certificates: Secure Boot certificates used by most Windows devices are set to expire starting June 2026. Microsoft has been deploying updated certificates to consumer and non-managed business devices. Devices that have not yet received newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. IT administrators should consult the Secure Boot Playbook for Windows clients and Windows Server for guidance.
Known issues
CertificateServicesClient error events logged on restart
Symptom: After installing the July 2025 non-security preview update (KB5062600) or any later update - including this August 2025 security update - Event Viewer may show an error related to CertificateServicesClient (CertEnroll): "The 'Microsoft Pluton Cryptographic Provider' provider was not loaded because initialization failed." This appears as Error ID 57 on every device restart. It is tied to a feature currently in development and has no impact on active Windows functionality. No action is required.
Workaround: This issue is addressed in KB5064081.
WSUS installation failure with error code 0x80240069
Symptom: KB5063878 may fail to install with error code 0x80240069 when deployed through Windows Server Update Services (WSUS). This issue is unlikely to affect home users, as WSUS is used in business and enterprise environments.
Workaround: The issue affecting the Windows Update service for WSUS-managed devices has been resolved. If you experienced this problem, refresh and re-sync with WSUS to install the update. A Known Issue Rollback (KIR) Group Policy was previously released as a workaround; organizations no longer need to install or configure that policy.
Network Device Interface (NDI) streaming performance degradation
Symptom: After installing this update, users may experience delays or uneven audio and video performance when using Network Device Interface (NDI) to stream or transfer feeds between PCs. The issue affects streaming applications such as OBS Studio and NDI Tools, particularly when Display Capture is enabled on the source PC, and can occur even under low-bandwidth conditions.
Workaround: This issue is addressed in KB5065426.
Unexpected UAC prompt during MSI repair operations
Symptom: A security improvement in this update enforces User Account Control (UAC) prompting for administrator credentials during Windows Installer (MSI) repair and related operations, addressing CVE-2025-50173. Standard users may now see UAC prompts when running MSI repair commands (such as msiexec /fu), opening certain Autodesk applications (including some versions of AutoCAD, Civil 3D, and Inventor CAM), installing apps that configure per user, running Windows Installer during Active Setup, deploying packages through Configuration Manager that rely on user-specific advertising configurations, or enabling Secure Desktop. If a non-admin user triggers an MSI repair operation without UI, it will fail - for example, running Office Professional Plus 2010 as a standard user may produce Error 1730 during configuration.
Workaround: This issue is addressed in KB5065426.
How to get this update
Microsoft bundles the latest servicing stack update (SSU) with the latest cumulative update (LCU) in a single package, so no separate SSU installation is required beforehand.
- Windows Update / Microsoft Update: The update downloads and installs automatically.
- Windows Update for Business: Downloads and installs automatically in accordance with configured policies.
- Microsoft Update Catalog: The standalone package is available for manual download. This KB contains multiple MSU files. You can install them all together using DISM with the
/PackagePathargument pointing to a folder containing all MSU files, or install them individually in the following order:windows11.0-kb5043080-x64first, thenwindows11.0-kb5063878-x64. DISM commands work from an elevated Command Prompt or elevated PowerShell. - WSUS: The update syncs automatically when Products is set to Windows 11 and Classification is set to Security Updates.
To remove the LCU after installation, use DISM /online /remove-package with the LCU package name. Using wusa.exe /uninstall on the combined package will not work because the SSU is included and cannot be removed after installation.
Frequently asked questions
Does this update apply to Windows Server or standard Windows PCs without Copilot+ hardware?
This update applies to Windows 11 version 24H2 on all editions. The AI component updates bundled in the package - covering Image Search, Content Extraction, Semantic Analysis, and Settings Model - are only applicable to Windows Copilot+ PCs. Those components will not install on standard Windows PCs or Windows Server machines.
Why are WSUS-managed devices encountering error 0x80240069, and what should admins do now?
A now-resolved issue caused KB5063878 to fail installation via WSUS with error code 0x80240069. Microsoft has addressed the problem on the service side. Administrators who experienced this should refresh and re-sync with WSUS. Any previously deployed KIR Group Policy for this issue no longer needs to remain configured.
What is the impact of the new UAC prompt behavior during MSI repairs introduced by this update?
The update enforces UAC prompting when standard users trigger MSI repair or related operations, addressing security vulnerability CVE-2025-50173. This may disrupt workflows involving Autodesk apps, ConfigMgr deployments using per-user advertising, or scripts that call msiexec /fu silently. The behavior change is by design. The issue causing unintended breakage in broader scenarios is resolved in KB5065426.
How should IT admins handle the Secure Boot certificate expiration warning?
Secure Boot certificates begin expiring in June 2026. Devices not yet updated will continue to start and function normally for now, and standard Windows updates will keep installing. Microsoft is continuing to roll out newer certificates via Windows Update. Admins managing enterprise fleets should review the Secure Boot Playbook for Windows clients and Windows Server, and can check device status individually through the Windows Security app.









