NAVANEM
Security updateOS build 22631.6345

KB5071417: Windows 11 23H2 Cumulative Update - December 9, 2025 (OS Build 22631.6345)

December 9, 2025 security cumulative update for Windows 11 version 23H2, delivering OS build 22631.6345 with security fixes and a PowerShell 5.1 improvement.

KB5071417: Windows 11 23H2 Cumulative Update - December 9, 2025 (OS Build 22631.6345) — navanem Microsoft KB cover
KB5071417 · Windows 11 · Security Update

Summary

KB5071417 is the December 9, 2025 monthly security cumulative update for Windows 11 version 23H2. It delivers OS build 22631.6345 and bundles the latest security fixes together with non-security improvements carried forward from November's optional preview release. Source: Microsoft Support.

Highlights

  • This update addresses security issues in the Windows operating system.

Improvements and fixes

  • PowerShell 5.1 - Invoke-WebRequest security prompt: The Invoke-WebRequest cmdlet now displays a confirmation prompt with a security warning about script execution risk when handling web content. Users can choose to continue or cancel. This change corresponds to CVE-2025-54100 and is documented separately in KB5074596.
  • Servicing stack update (KB5071963, version 22621.6265): A companion servicing stack update ships with this package, improving the reliability and quality of the component responsible for installing Windows updates.
  • Prior quality improvements included: All fixes from KB5068865, released November 11, 2025, are incorporated into this package.

Announcements

Two notable announcements accompany this release:

  • Secure Boot certificate expiration: Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. Microsoft has been rolling out updated certificates to consumer and non-managed business devices for several months. Devices that have not yet received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. IT administrators should consult the Secure Boot Playbook for Windows clients and Windows Server. Device certificate status can be checked in the Windows Security app.
  • Microsoft Store apps: This update does not include updates for Microsoft Store apps. Enterprise users should refer to Microsoft Store apps documentation for Configuration Manager; consumer users should use the Get updates for apps and games in Microsoft Store guidance.

Known issues

Microsoft lists no known issues for this update at the time of writing.

How to get this update

Microsoft bundles the latest servicing stack update (SSU) with the latest cumulative update (LCU) in a single package. No separate SSU installation step is required before deploying KB5071417.

The update is available through the following channels:

  • Windows Update / Microsoft Update: Downloads and installs automatically.
  • Windows Update for Business: Deploys automatically in line with configured policies.
  • Microsoft Update Catalog: Standalone package available for manual download.
  • Windows Server Update Services (WSUS): Syncs automatically when Products and Classifications are set to Product: Windows 11 and Classification: Security Updates.

Removing the LCU: If you need to remove the LCU after installing the combined SSU and LCU package, use the DISM /Remove-Package command with the LCU package name as the argument. Running wusa.exe /uninstall against the combined package will not work because it contains the SSU, and the SSU cannot be removed from the system after installation. Use DISM /online /get-packages to find the correct package name.

Important prerequisite: To update a device to Windows 11 version 23H2 before applying this update, use KB5027397.

File information for the cumulative update (KB5071417) and the servicing stack update (KB5071963, version 22621.6265) is available as separate downloads from the Microsoft Support page.

Frequently asked questions

Does this update include non-security fixes or only security patches?

This package includes both. It carries all security fixes for December 2025 and also rolls in the non-security quality improvements that shipped in November's optional preview release (KB5068865, released November 11, 2025). Devices that already installed previous cumulative updates will download only the new components added in this package.

What is the PowerShell 5.1 change, and does it affect scripts in production environments?

Invoke-WebRequest now shows a confirmation prompt and security warning when there is a script execution risk from web content. This relates to CVE-2025-54100. Administrators running automated scripts that use Invoke-WebRequest should review KB5074596 for full details and test pipelines before broad deployment to avoid unexpected interactive prompts breaking automation.

Do I need to install a separate servicing stack update before deploying KB5071417?

No. Microsoft combines the latest SSU (KB5071963, version 22621.6265) with this LCU in a single package. The combined package installs both components together, so there is no separate SSU pre-installation step required on Windows 11 version 23H2 devices.

How does the Secure Boot certificate expiration affect managed enterprise devices?

Microsoft has been distributing updated Secure Boot certificates via Windows Update for consumer and non-managed business devices. Managed devices that have not yet received the newer certificates will continue to boot and operate normally, and standard Windows updates will still install. IT administrators managing enterprise fleets should follow the Secure Boot Playbook for Windows clients and Windows Server to plan certificate updates proactively before the June 2026 expiration window begins.

#windows-11#23h2#security-update#cumulative-update#PowerShell#secure-boot#patch-tuesday

Related topics