NAVANEM
Security updateOS build 17763.8276

KB5073723: January 13, 2026 Security Update for Windows Server 2019 and Windows 10 LTSC 2019 (OS Build 17763.8276)

Security update for Windows Server 2019 and Windows 10 Enterprise LTSC 2019, bringing OS build to 17763.8276. Released January 13, 2026.

KB5073723: January 13, 2026 Security Update for Windows Server 2019 and Windows 10 LTSC 2019 (OS Build 17763.8276) — navanem Microsoft KB cover
KB5073723 · Windows Server · Security Update

Summary

KB5073723 is a security update for Windows Server 2019 and Windows 10 Enterprise LTSC 2019, raising the OS build to 17763.8276. Released on January 13, 2026, it includes fixes and quality improvements that build on the December 9, 2025 update (KB5071544) and the December 18, 2025 out-of-band update (KB5074975). See Microsoft Support for the official page.

Improvements and fixes

The following changes apply to Windows Server 2019 with this update:

  • Credentials autofill hardening: A new security behavior restricts certain applications from autofilling credentials during remote support sessions or automated authentication workflows. Credential dialogs no longer respond to virtual keyboard input sent by remote desktop or screen-sharing tools.
  • Windows Deployment Services (WDS) change: WDS now stops supporting hands-free deployment functionality by default. Administrators should review the WDS Hands-Free Deployment Hardening Guidance for instructions on how to proceed.
  • Modem driver removal: The following modem drivers have been removed: agrsm64.sys (x64), agrsm.sys (x86), smserl64.sys (x64), and smserial.sys (x86). Modem hardware that depends on these specific drivers will no longer function in Windows.
  • WinSqlite3.dll update: The Windows core component WinSqlite3.dll has been updated. Previously, some security software flagged this component as vulnerable. Note that WinSqlite3.dll is separate from sqlite3.dll, which is found in application-specific directories and is not a Windows component.

The following changes apply to Windows 10 Enterprise LTSC 2019 with this update:

  • Credentials autofill hardening: Same restriction as described above for Server 2019 - credential dialogs do not respond to virtual keyboard input from remote desktop or screen-sharing tools during remote support or automated authentication workflows.
  • Modem driver removal: The same four modem drivers (agrsm64.sys, agrsm.sys, smserl64.sys, smserial.sys) are removed. Dependent modem hardware will stop working.
  • WinSqlite3.dll update: Same fix as described above for Server 2019.

This update also includes a combined servicing stack update (SSU KB5074222, version 17763.8260), which improves the reliability of the update installation process.

Known issues

Japanese characters fail to render correctly in PowerShell

Symptom: On Japanese language installations of Windows Server 2019, after installing this update (released on or after January 13, 2026), Japanese characters may not display correctly in the PowerShell console. An unintended change sets PowerShell encoding to UTF-8, causing Japanese output text to appear garbled or replaced with question marks. Japanese text entered into PowerShell is also affected. English text and command entry work normally.

Workaround: This issue is resolved in Windows updates released on and after April 14, 2026 (such as KB5082123). Microsoft recommends installing the latest Windows update.

Connection and authentication failures in Azure Virtual Desktop and Windows 365

Symptom: After installing this security update, credential prompt failures occurred during Remote Desktop connections using the Windows App on Windows client devices, affecting Azure Virtual Desktop and Windows 365. The issue causes sign-in failures on specific Windows builds.

Workaround: This issue is resolved in Windows updates released on and after January 17, 2026 (such as KB5077795). Microsoft recommends installing the latest Windows update.

Apps might become unresponsive when saving files to cloud-based storage

Symptom: After installing this update, some applications may become unresponsive or encounter unexpected errors when opening or saving files to cloud-based storage such as OneDrive or Dropbox. In certain Outlook configurations where PST files are stored on OneDrive, Outlook may hang and fail to reopen unless the process is terminated or the system is restarted. Users may also see missing sent items or previously downloaded emails being re-downloaded.

Workaround: This issue is addressed in KB5078131.

Some devices with Virtual Secure Mode enabled might fail to shut down or hibernate

Symptom: After installing this update, some Secure Launch-capable PCs with Virtual Secure Mode (VSM) enabled are unable to shut down or enter hibernation. Instead, the device restarts.

Workaround: This issue is addressed in KB5075904.

How to get this update

Before installing KB5073723, you must have the August 10, 2021 SSU (KB5005112) installed. Once that prerequisite is in place, the update is available through the following channels:

  • Windows Update / Microsoft Update: Downloaded and installed automatically.
  • Windows Update for Business: Distributed automatically in accordance with configured policies.
  • Microsoft Update Catalog: The standalone package can be downloaded directly from the catalog website.
  • Windows Server Update Services (WSUS): The update syncs automatically when Products is set to Windows 10 and Classification is set to Security Updates.

To remove only the LCU after installing the combined SSU and LCU package, use the DISM /Remove-Package command with the LCU package name as the argument. Running wusa.exe with the /uninstall switch on the combined package will not work because the SSU is included and cannot be removed after installation.

Frequently asked questions

Does this update apply to both Windows Server 2019 and Windows 10 Enterprise LTSC 2019?

Yes. KB5073723 applies to both Windows Server 2019 and Windows 10 Enterprise LTSC 2019, both of which share OS build 17763.8276. The full list of improvements differs slightly between the two products - the WDS hands-free deployment change, for example, applies only to Windows Server 2019 and is not listed for the LTSC 2019 client.

What is the prerequisite before installing this update?

You must have the August 10, 2021 servicing stack update (KB5005112) installed before you can apply this cumulative update. The update itself also bundles a new SSU (KB5074222, build 17763.8260) to improve update reliability going forward.

What should administrators know about the credentials autofill change?

This update introduces a security hardening behavior that blocks certain applications from autofilling credentials during remote support or automated authentication workflows. Credential dialogs will no longer accept virtual keyboard input from remote desktop or screen-sharing tools. Administrators should review the guidance at the linked Microsoft support article before deployment to avoid disruption to remote support processes.

When do Windows Server 2019 and Windows 10 Enterprise LTSC 2019 reach end of support?

Both products are scheduled to reach end of support on January 9, 2029. After that date, Microsoft will no longer provide free software updates from Windows Update, technical assistance, or security fixes. Microsoft recommends planning an upgrade to a later version of Windows Server before that deadline.

#windows-server-2019#windows-10-ltsc#security-update#patch-tuesday#credentials-autofill#wds#sqlite

Related topics