NAVANEM
Security updateOS build 20348.4106

September 2025 Hotpatch KB5065306 for Windows Server 2022 Datacenter: Azure Edition (OS Build 20348.4106)

September 9, 2025 hotpatch security update for Windows Server 2022 Datacenter: Azure Edition, bringing OS Build 20348.4106 and fixing unexpected UAC prompts during MSI repair operations.

KB5065306: September 2025 Hotpatch KB5065306 for Windows Server 2022 Datacenter: Azure Edition (OS Build 20348.4106) — navanem Microsoft KB cover
KB5065306 · Windows Server · Security Update

Summary

This is a hotpatch security update for Windows Server 2022 Datacenter: Azure Edition, released on September 9, 2025, producing OS Build 20348.4106. It delivers quality improvements focused on application compatibility, specifically addressing unexpected UAC prompts triggered during MSI repair operations. Full details are documented on Microsoft Support.

Improvements and fixes

  • UAC prompt fix for MSI installers: Resolves an issue where non-admin users received unexpected User Account Control (UAC) prompts when MSI installers performed certain custom actions - such as configuration or repair operations running in the foreground or background during initial application installation. This problem blocked non-admin users from running apps that rely on MSI repair, including Office Professional Plus 2010 and multiple Autodesk products such as AutoCAD. The fix reduces the scope of scenarios that require UAC prompts for MSI repairs and gives IT admins the ability to disable UAC prompts for specific applications by adding them to an allowlist. Microsoft links this fix to a known issue introduced by the August 2025 Windows security update.

Known issues

PSDirect connections failing in hotpatched devices

Symptom: An edge case affects hotpatched devices that have installed the September 2025 Hotpatch update (KB5065306) or the September 2025 security update (KB5065432). These devices may experience failures with PowerShell Direct (PSDirect) connections when the host and guest virtual machines are not both fully updated. When a patched guest VM attempts to connect to an unpatched host - or the reverse - the system is expected to fall back to a legacy handshake and clean up the socket gracefully. This fallback mechanism fails intermittently, causing socket cleanup issues. The connection failure may appear random, and Event ID 4625 may be logged in the Security Event log within Windows Event Viewer.

Workaround: This issue is addressed in KB5066359. Microsoft recommends updating both the host and guest VM with these updates if the hotpatched device is experiencing PSDirect connection failures.

How to get this update

Microsoft now combines the latest servicing stack update (SSU) with the hotpatch update. If you use Windows Update or Windows Server Update Services (WSUS), the latest SSU installs automatically alongside this update. No separate SSU installation step is required. File information for the SSU (KB5065769, version 20348.4160) is available separately from Microsoft.

This update is available through the following channels:

  • Windows Update / Microsoft Update: Downloads and installs automatically.
  • Windows Update Catalog: Available for manual download.
  • Windows Server Update Services (WSUS): Syncs automatically when Products and Classifications are configured as follows - Product: Server 2022 Hotpatch Category; Classification: Security Updates.

Frequently asked questions

Does this update require a restart?

Hotpatch updates are designed to apply security fixes to in-memory code on running processes without requiring a system reboot. This is the core advantage of the hotpatch mechanism on Windows Server 2022 Datacenter: Azure Edition. The page does not state that a restart is required for this specific update.

Which applications were blocked by the UAC issue this update fixes?

Microsoft specifically identifies Office Professional Plus 2010 and multiple Autodesk applications - including AutoCAD - as affected by the unexpected UAC prompt problem. The fix reduces the conditions under which UAC prompts appear during MSI repairs and introduces an allowlist mechanism for IT admins to exempt specific applications.

What should I do about the Secure Boot certificate expiration notice?

Microsoft notes that Secure Boot certificates on most Windows devices are set to expire starting in June 2026. Consumer and non-managed business devices have been receiving updated certificates for several months. Devices that have not yet received the newer certificates will continue to start and operate normally, and standard Windows updates will still install. IT administrators should follow the Secure Boot Playbook guidance for Windows clients and Windows Server.

Is the PSDirect issue resolved in this update itself?

No. The PSDirect connection failure is a known issue introduced by this update. The resolution is delivered in a separate update, KB5066359. Microsoft recommends applying KB5066359 to both the host and the guest VM to fully address the intermittent socket cleanup failures affecting PowerShell Direct connections.

#hotpatch#windows-server-2022#security-update#uac#msi-repair#psdirect#azure-edition