KB5072033: Windows 11 Security Update for Builds 26200.7462 and 26100.7462 (December 2025)
December 9, 2025 cumulative security update for Windows 11 versions 25H2 and 24H2, delivering OS builds 26200.7462 and 26100.7462 with security fixes and quality improvements.

Summary
KB5072033 is the December 9, 2025 cumulative security update for Windows 11 versions 25H2 and 24H2, producing OS builds 26200.7462 and 26100.7462. Released on December 9, 2025, it delivers the latest security fixes alongside non-security improvements carried over from last month's optional preview release. See the Microsoft Support page for full details.
Highlights
- This update addresses security issues for the Windows operating system.
Improvements and fixes
- Copilot - Click to Do window: Fixes a problem where the Ask Copilot feature did not bring the Click to Do window to the foreground when sharing data with Copilot. The window now activates as expected.
- File Explorer flash (known issue fix): Resolves a brief white flash that appeared when navigating between pages in File Explorer, a regression introduced by the December 1, 2025 optional preview update (KB5070311).
- Networking - virtual switch NIC binding loss: Fixes an issue where external virtual switches lost their physical NIC bindings after a host restart, causing the switches to fall back to internal mode and cutting off network connectivity for virtual machines. This blocked normal server operations.
- PowerShell 5.1 - Invoke-WebRequest security prompt: The
Invoke-WebRequestcmdlet now displays a confirmation prompt with a security warning about script execution risk before proceeding, allowing the user to continue or cancel. This addresses CVE-2025-54100; additional details are in KB5074596. - AppX Deployment Service (Appxsvc) startup type: The AppX Deployment Service has been changed to Automatic startup type to improve reliability in certain isolated scenarios.
- AI component updates: The following AI components are updated to version 1.2511.1224.0: Image Search, Content Extraction, Semantic Analysis, and Settings Model. These components apply only to Windows Copilot+ PCs and will not install on standard Windows PCs or Windows Server.
Known issues
Password icon missing or invisible on the lock screen
Symptom: After installing the August 2025 non-security preview update (KB5064081) or any later update, the password icon may not appear in the sign-in options on the lock screen. Hovering over the blank area confirms the button is still present and functional. Clicking the placeholder opens the password text box, allowing normal sign-in. This issue primarily affects enterprise or managed IT environments; users on Windows Home or Pro personal devices are very unlikely to encounter it.
Workaround: This issue is addressed in KB5074105.
Mirror networking in WSL may fail with some VPN clients
Symptom: After installing the October 2025 non-security update (KB5067036, released October 28, 2025) or a later update, mirrored networking mode in Windows Subsystem for Linux (WSL) may cause failures with certain third-party VPNs. Affected users see a "No route to host" error even though the Windows host itself can reach the same destinations. This can block access to corporate resources over VPN. The root cause is that the VPN application's virtual interface does not respond to ARP requests. Cisco Secure Client (formerly Cisco AnyConnect) and OpenVPN are reported as affected. Home users on Windows Home or Pro are unlikely to experience this issue.
Workaround: This issue is addressed in KB5074109.
RemoteApp sessions may fail to start on Azure Virtual Desktop
Symptom: After installing the November 2025 non-security preview update (KB5070311) or a later update, RemoteApp connections in Azure Virtual Desktop (AVD) environments may fail to start. Full desktop sessions are not affected. This issue primarily affects enterprise environments; users on Windows Home or Pro personal devices are very unlikely to encounter it.
Workaround: This issue is addressed in KB5074109.
How to get this update
Microsoft bundles the latest servicing stack update (SSU) - KB5071142, version 26100.7295 - together with the cumulative update package, so no separate SSU installation step is required before applying KB5072033.
- Windows Update / Microsoft Update: The update downloads and installs automatically.
- Windows Update for Business: Deploys automatically in line with configured policies.
- Microsoft Update Catalog: Download the standalone package manually. Two MSU files are available. You can install them together by placing both in the same folder and running DISM with the
/Add-Packageoption against the main KB5072033 MSU file - DISM will resolve the prerequisite automatically - or install them individually in order: firstwindows11.0-kb5043080-x64thenwindows11.0-kb5072033-x64. - Windows Server Update Services (WSUS): Syncs automatically when the Product is set to Windows 11 and Classification is set to Security Updates.
Note: To remove only the cumulative update after installation, use DISM /online /remove-package with the LCU package name. Running wusa.exe /uninstall against the combined package will not work because the SSU is embedded in it, and the SSU cannot be removed once installed.
Frequently asked questions
Does this update include the December 2025 optional non-security preview content?
Yes. KB5072033 incorporates fixes and quality improvements from KB5070311, the optional preview update released December 1, 2025. Devices that already installed that preview update will download only the additional new changes included in this security release.
Will the AI component updates install on all Windows 11 devices?
No. Although the AI component updates are packaged inside KB5072033, they apply only to Windows Copilot+ PCs. They will not install on standard Windows PCs or Windows Server hardware that does not meet the Copilot+ requirements.
Is there a non-security preview update scheduled for late December 2025?
No. Microsoft has stated that due to reduced operations during the Western holiday period and New Year's Day, there will be no December 2025 non-security preview update in the second half of the month. Regular monthly servicing - including both security updates and non-security preview updates - will resume in January 2026.
What should administrators know about the upcoming Secure Boot certificate expiration?
Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. Microsoft has been deploying updated certificates to consumer and non-managed business devices in recent months. Devices that have not yet received the new certificates will continue to start and operate normally, and standard Windows updates will continue to install. Administrators should follow guidance on the Secure Boot Playbook for Windows clients and Windows Server, and can check device status in the Windows Security app.









