NAVANEM
Security updateOS build 22631.6491

KB5073455: Windows 11 version 23H2 Security Update (OS Build 22631.6491) - January 2026

January 13, 2026 cumulative security update for Windows 11 version 23H2, delivering OS build 22631.6491 with security fixes, quality improvements, and credential autofill hardening.

KB5073455: Windows 11 version 23H2 Security Update (OS Build 22631.6491) - January 2026 — navanem Microsoft KB cover
KB5073455 · Windows 11 · Security Update

Summary

This is the January 13, 2026 cumulative security update for Windows 11, version 23H2, producing OS Build 22631.6491. Released on January 13, 2026, it carries the latest security fixes alongside non-security improvements from the previous month's optional preview. It applies to all editions of Windows 11, version 23H2. See the Microsoft Support page for full details.

Highlights

  • A security hardening change restricts certain applications from autofilling credentials during remote support sessions or automated authentication workflows, so credential dialogs no longer respond to virtual keyboard input from remote desktop or screen-sharing tools.
  • The modem drivers agrsm64.sys, agrsm.sys, smserl64.sys, and smserial.sys are removed; hardware dependent on those drivers will no longer function in Windows.
  • Windows quality updates now include a subset of high-confidence device-targeting data to identify devices eligible to receive updated Secure Boot certificates automatically, using a phased deployment approach.

Improvements and fixes

  • Compatibility: Four legacy modem drivers - agrsm64.sys (x64), agrsm.sys (x86), smserl64.sys (x64), and smserial.sys (x86) - are removed. Any modem hardware that relies on these specific drivers will stop working after this update is installed.
  • Credentials autofill: A security hardening behavior is introduced that prevents certain applications from autofilling credentials during remote support sessions or automated authentication workflows. Credential dialogs will no longer accept virtual keyboard input from remote desktop or screen-sharing applications.
  • Display Kernel: A bug causing Remote Desktop Protocol (RDP) connections to fail, sometimes requiring a device restart, has been fixed.
  • Input: A crash affecting apps including Outlook, Teams, Edge, Chrome, and Excel, where those apps could close unexpectedly while text was being entered, has been resolved.
  • Secure Boot: Starting with this update, Windows quality updates carry a subset of high-confidence device-targeting data identifying devices eligible to receive new Secure Boot certificates automatically. Devices receive the new certificates only after showing sufficient successful update signals, ensuring a safe and staged rollout.
  • WinSqlite3.dll: The Windows core component WinSqlite3.dll has been updated to address a condition where some security software might flag it as vulnerable. Note that WinSqlite3.dll is separate from sqlite3.dll, which is found in application-specific directories and is not a Windows component. If security software continues to flag sqlite3.dll, contact the developer of the relevant application.

This update also includes a bundled servicing stack update, KB5071963 (version 22621.6265), which improves the component responsible for installing Windows updates.

Known issues

Connection and authentication failures in Azure Virtual Desktop and Windows 365

Symptom: After installing this update, credential prompt failures occur during Remote Desktop connections using the Windows App on Windows client devices, affecting Azure Virtual Desktop and Windows 365. The issue causes sign-in failures on specific Windows builds.

Workaround: This issue is addressed in KB5077797.

Secure Launch-capable devices might fail to shut down or hibernate

Symptom: After installing this update, some PCs capable of using Secure Launch are unable to shut down or enter hibernation, and the device restarts instead.

Workaround: This issue is fully resolved in Windows updates released on February 10, 2026 (KB5075941) and in all updates released after that date. The fix covers devices using Secure Launch and devices with Virtual Secure Mode (VSM) enabled. An earlier partial fix was released via the Microsoft Update Catalog in an out-of-band update on January 17, 2026 (KB5077797), and later through Windows Update in an out-of-band update on January 24, 2026 (KB5078132).

Apps might become unresponsive when saving files to cloud-based storage

Symptom: After installing this update, some applications may become unresponsive or encounter unexpected errors when opening or saving files to cloud-based storage such as OneDrive or Dropbox. In certain Outlook configurations that store PST files on OneDrive, Outlook may hang and fail to reopen unless the process is terminated or the system is restarted. Users may also see missing sent items or previously downloaded emails being re-downloaded.

Workaround: This issue is addressed in KB5078132.

How to get this update

Microsoft bundles the latest servicing stack update (SSU) with this cumulative update, so no separate SSU installation is needed. The update is available through the following channels:

  • Windows Update / Microsoft Update: Downloads and installs automatically.
  • Windows Update for Business: Deploys automatically in accordance with configured policies.
  • Microsoft Update Catalog: Download the standalone package directly from the catalog.
  • Windows Server Update Services (WSUS): Syncs automatically when Products and Classifications are configured with Product set to "Windows 11" and Classification set to "Security Updates".

To remove only the cumulative update after installation, use the DISM /online /remove-package command with the LCU package name. Running wusa.exe with the /uninstall switch will not work on the combined package because it contains the SSU, and the SSU cannot be removed after installation.

To upgrade to Windows 11, version 23H2, use the enablement package KB5027397.

Frequently asked questions

Does this update change how credential autofill works during remote support sessions?

Yes. This update introduces a security hardening behavior that blocks certain applications from autofilling credentials during remote desktop or screen-sharing sessions. Credential dialogs will no longer accept virtual keyboard input from remote desktop or screen-sharing tools, which may affect automated authentication workflows and some remote support scenarios.

What should I do if devices fail to shut down or hibernate after installing this update?

The shutdown and hibernation issue affecting Secure Launch-capable devices and devices with Virtual Secure Mode enabled is fully resolved by the February 10, 2026 update (KB5075941). Install that update or any update released after that date to fully resolve the problem on affected devices.

Are the removed modem drivers likely to affect my environment?

Only hardware that depends specifically on agrsm64.sys, agrsm.sys, smserl64.sys, or smserial.sys will be affected. These are older modem drivers. If your environment does not use modems relying on these drivers, no action is needed. Verify hardware compatibility before deploying this update to systems that use legacy modem hardware.

Is the Secure Boot certificate update included in this release?

This update introduces device-targeting data that identifies devices eligible to receive new Secure Boot certificates. Certificates are delivered only after a device demonstrates sufficient successful update signals. Microsoft notes that devices without the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install.

#windows-11#security-update#cumulative-update#secure-boot#Remote Desktop#credentials#23h2

Related topics