NAVANEM
Security updateOS build 19045.6809 and 19044.6809

KB5073724: Windows 10 January 13 2026 Security Update (OS Builds 19045.6809 and 19044.6809)

January 13 2026 security update for Windows 10 version 22H2 and LTSC 2021, delivering OS builds 19045.6809 and 19044.6809 with security fixes and quality improvements.

KB5073724: Windows 10 January 13 2026 Security Update (OS Builds 19045.6809 and 19044.6809) — navanem Microsoft KB cover
KB5073724 · Windows 10 · Security Update

Summary

KB5073724 is a security update for Windows 10 version 22H2 and Windows 10 Enterprise LTSC 2021, released on January 13, 2026. It produces OS builds 19045.6809 and 19044.6809. The update addresses security vulnerabilities and delivers quality improvements across credentials handling, driver management, Secure Boot certificate deployment, and a core SQLite component fix. Source: Microsoft Support

Improvements and fixes

  • Credentials autofill: A security hardening change now restricts certain applications from autofilling credentials during remote support sessions or automated authentication workflows. Credential dialogs no longer respond to virtual keyboard input sent by remote desktop or screen sharing tools. Microsoft has published a separate article detailing this new behavior.
  • Driver removal: Four legacy modem drivers have been removed from Windows - agrsm64.sys (x64), agrsm.sys (x86), smserl64.sys (x64), and smserial.sys (x86). Any modem hardware that depends on these specific drivers will stop functioning after this update is installed.
  • Secure Boot certificate deployment: Starting with this update, Windows quality updates include a subset of high-confidence device targeting data to identify devices eligible to receive new Secure Boot certificates automatically. Certificates are delivered only after the device demonstrates sufficient successful update signals, supporting a phased rollout.
  • WinSqlite3.dll updated: The Windows core component WinSqlite3.dll has been updated. Previously, some security software flagged this component as vulnerable. Note that WinSqlite3.dll is separate from sqlite3.dll found in application directories; if security tools continue to flag sqlite3.dll, contact the application developer or update the relevant Microsoft app from the Microsoft Store.

Known issues

Connection and authentication failures in Azure Virtual Desktop and Windows 365

Symptom: After installing this security update, credential prompt failures occurred during Remote Desktop connections using the Windows App on Windows client devices, affecting Azure Virtual Desktop and Windows 365. The issue causes sign-in failures on specific Windows builds.

Workaround: This issue is resolved in Windows updates released on and after January 17, 2026 (such as KB5077796). Microsoft recommends installing the latest Windows update for your device.

Apps might become unresponsive when saving files to cloud-based storage

Symptom: After installing this update, some applications may become unresponsive or encounter unexpected errors when opening or saving files in cloud-based locations. In certain Outlook configurations where PST files are stored on OneDrive, Outlook may hang and fail to reopen unless the process is terminated or the system is restarted. Users may also see missing sent items or previously downloaded emails being re-downloaded.

Workaround: This issue is addressed in KB5078129.

Some devices with Virtual Secure Mode enabled might fail to shut down or hibernate

Symptom: After installing this update, some Secure Launch-capable PCs with Virtual Secure Mode (VSM) enabled are unable to shut down or enter hibernation. Instead, the device restarts.

Workaround: This issue is addressed in KB5075912.

How to get this update

Before installing, the latest servicing stack update (SSU) must be in place. Failing to install the latest SSU first may prevent Windows Update from offering the cumulative update. Two specific prerequisite scenarios apply:

  • Offline OS image servicing: If the image does not have the July 25, 2023 (KB5028244) or later LCU, install the standalone October 13, 2023 SSU (KB5031539) first.
  • WSUS or Microsoft Update Catalog standalone install: If devices do not have the May 11, 2021 (KB5003173) or later LCU, install the standalone August 10, 2021 SSU (KB5005260) first.

This update is available through the following channels:

  • Windows Update and Microsoft Update - downloaded and installed automatically.
  • Windows Update for Business - deployed automatically in line with configured policies.
  • Microsoft Update Catalog - standalone package available for direct download.
  • Windows Server Update Services (WSUS) - syncs automatically when Product is set to "Windows 10, version 1903 and later" and Classification is set to "Security Updates".

This update also bundles the servicing stack update KB5068780 (versions 19045.6575 and 19044.6575). The SSU includes updated logic to verify whether a device is hosted on Azure using an updated certificate chain. Microsoft strongly recommends installing this SSU before applying additional updates on Azure-hosted devices, and ensuring the device can reach the required certificate update domains.

To remove only the LCU after installing the combined SSU and LCU package, use the DISM /online /remove-package command with the LCU package name. Running wusa.exe /uninstall against the combined package will not work because the SSU is included and cannot be removed after installation.

Frequently asked questions

Does this update apply to Windows 10 Home and Pro editions?

Based on what Microsoft states on the support page, KB5073724 applies to Windows 10 ESU and Windows 10 Enterprise LTSC 2021. Windows 10 version 22H2 users should use EKB KB5015684 to update to that version before this update applies. The page does not specifically list Home or Pro as covered editions.

Why did my modem stop working after applying this update?

This update removes four legacy modem drivers - agrsm64.sys, agrsm.sys, smserl64.sys, and smserial.sys. If your modem hardware relied on any of these specific drivers, it will no longer function in Windows after this update is installed. Check with your hardware vendor for a replacement driver.

What should I know about the credentials autofill change introduced by this update?

This update adds a security hardening behavior that prevents credential dialogs from responding to virtual keyboard input from remote desktop or screen sharing applications. This may affect remote support workflows or automated authentication processes. Microsoft has published a separate article with more details titled "New behavior restricting certain applications to autofill credentials introduced by the Windows January 2026 security update."

Are the Secure Boot certificate expiration warnings in Windows Security app a sign that my device is at risk?

According to Microsoft, devices that have not yet received the newer Secure Boot certificates will continue to start and operate normally, and standard Windows updates will continue to install. Microsoft states it will continue deploying the updated certificates via Windows updates in the coming months. IT administrators should consult the Secure Boot Playbook for Windows clients and Windows Server for guidance.

#windows-10#security-update#secure-boot#credentials-autofill#ltsc-2021#22h2#january-2026

Related topics