NAVANEM
Security updateOS build 20348.4052

KB5063880: Windows Server 2022 Security Update (OS Build 20348.4052) - August 12, 2025

August 12, 2025 security update for Windows Server 2022, bringing OS to build 20348.4052. Fixes a Traditional Chinese IME input issue and addresses security vulnerabilities.

KB5063880: Windows Server 2022 Security Update (OS Build 20348.4052) - August 12, 2025 — navanem Microsoft KB cover
KB5063880 · Windows Server · Security Update

Summary

KB5063880 is the August 12, 2025 security update for Windows Server 2022, bringing the OS to build 20348.4052. It includes quality improvements carried forward from the July 2025 cumulative update and resolves a known input method editor (IME) issue. This update also bundles a servicing stack update. Source: Microsoft Support.

Improvements and fixes

  • This update carries forward all fixes and quality improvements from KB5062572, which was released on July 8, 2025.
  • Resolves an issue with the Microsoft Changjie IME for Traditional Chinese input where users could experience problems forming or selecting words, an unresponsive spacebar or blank key, incorrect word output, or a broken candidate window display. This problem could appear after installing KB5062572.
  • Includes security fixes documented in the August 2025 Security Updates; full details are available in the Security Update Guide.
  • Bundles servicing stack update KB5062793 (version 20348.3920), which improves the reliability and quality of the component responsible for installing Windows updates.

Known issues

Unexpected UAC prompt during MSI repair operations

Symptom: The August 2025 security update enforces a requirement that User Account Control (UAC) prompt for administrator credentials when Windows Installer (MSI) repair and related operations are performed, addressing security vulnerability CVE-2025-50173. After installing this update, standard users may see unexpected UAC prompts or failures in several scenarios: running MSI repair commands such as msiexec /fu; opening Autodesk applications including some versions of AutoCAD, Civil 3D, and Inventor CAM, or installing an MSI file after first sign-in; installing apps that configure on a per-user basis; running Windows Installer during Active Setup; deploying packages through Configuration Manager (ConfigMgr) that rely on user-specific advertising configurations; and enabling Secure Desktop. If a non-admin user runs an app that triggers a silent MSI repair, it will fail with an error. For example, installing and running Office Professional Plus 2010 as a standard user will fail with Error 1730 during configuration.

Workaround: This issue is addressed in KB5065432.

How to get this update

Before installing, note that Microsoft now combines the latest servicing stack update (SSU) with the latest cumulative update (LCU) in a single package. For offline OS image servicing, confirm that your image includes KB5030216 (released 09/12/2023) or a later LCU. Without it, install that update on your offline media first, as it brings the SSU to version 20348.1960 - the minimum required to avoid error 0x800f0823 (CBS_E_NEW_SERVICING_STACK_REQUIRED).

This update is available through the following channels:

  • Windows Update / Microsoft Update - downloads and installs automatically.
  • Windows Update for Business - downloads and installs automatically in accordance with configured policies.
  • Microsoft Update Catalog - standalone package available for manual download. Note that the package includes AI component updates, but those components only apply to Windows Copilot+ PCs and will not install on standard Windows PCs or Windows Server.
  • Windows Server Update Services (WSUS) - syncs automatically when Products and Classifications are configured as: Product - Microsoft Server operating system-21H2; Classification - Security Updates.

To remove only the LCU after installation, use the DISM /Remove-Package command with the LCU package name as the argument. Running wusa.exe with the /uninstall switch will not work on the combined package because it contains the SSU, and the SSU cannot be removed after installation.

Frequently asked questions

Does this update include fixes from previous months?

Yes. KB5063880 is a cumulative update, so it carries forward all improvements and fixes from KB5062572, released July 8, 2025, and earlier updates. Administrators do not need to install prior monthly updates separately before deploying this package.

What should I do about the Secure Boot certificate expiration warning?

Microsoft notes that Secure Boot certificates on most Windows devices are set to expire starting June 2026. Devices that have not yet received updated certificates will continue to start and operate normally, and standard Windows updates will keep installing. Microsoft is continuing to distribute the newer certificates through Windows Update. IT administrators should consult the Secure Boot Playbook for Windows clients and Windows Server for specific guidance.

How do I address the UAC prompt issue affecting MSI repair operations?

The UAC prompt behavior is an intentional security enforcement tied to CVE-2025-50173, introduced in this update. If the change is causing problems in your environment - particularly with Configuration Manager deployments, Autodesk apps, or Office 2010 - Microsoft states the issue is resolved in KB5065432. Apply that update to affected systems.

Is the servicing stack update separate from this cumulative update?

No. Microsoft now bundles the servicing stack update (SSU KB5062793, version 20348.3920) directly into the cumulative update package. You do not need to download or install it separately. However, because the combined package includes the SSU, you cannot uninstall the SSU from the system once installed.

#windows-server-2022#security-update#ime-fix#uac#servicing-stack#cumulative-update

Related topics