Views
4

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

Update Summary

KB5082052 updates Windows 11 version 23H2 to OS Build 22631.6936 with security fixes, quality improvements, Secure Boot enhancements, SMB over QUIC reliability improvements, and Remote Desktop phishing protections. It also includes the servicing stack update KB5086307. Reference IDs: KB5027397, KB5078883, KB5087420.

Update Details

Security

  • Adds known vulnerable kernel drivers to the Microsoft vulnerable driver blocklist.
  • Improves protection against phishing attacks using Remote Desktop (.rdp) files by showing connection settings before connecting and adding a one-time security warning.
  • Addresses an issue where the device might enter BitLocker Recovery after Secure Boot updates.
  • Includes latest security fixes for Windows operating system vulnerabilities.

Bug Fixes

  • Fixes a sign-in issue where some users saw a 'no Internet' error when signing in to Microsoft account apps and services despite having connectivity.
  • Improves reliability of SMB compression over QUIC so requests complete more consistently and timeouts are less likely.
  • Includes quality improvements from KB5078883.
  • Adds a servicing stack update to improve update installation reliability.

New Features

  • Shows Secure Boot certificate update status in the Windows Security app with badges and notifications.
  • Uses additional high-confidence device targeting data to expand controlled rollout of new Secure Boot certificates.

Known Issues

  • Devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing the update.
  • Remote Desktop security warnings might not display correctly on multi-monitor setups with different display scaling settings.

Hints

  • Use EKB KB5027397 to update to Windows 11, version 23H2.
  • Microsoft recommends auditing BitLocker Group Policy settings for explicit PCR7 inclusion before installing the update.
  • For affected BitLocker devices, set the TPM platform validation profile policy to Not Configured, run gpupdate /force, then suspend and re-enable BitLocker protectors.
  • The Remote Desktop warning display issue is addressed in KB5087420.
  • Secure Boot certificates used by most Windows devices are set to expire starting in June 2026.
Product Information

Vendor: Microsoft

Product: Windows 11

Version: OS Build 22631.6936

Release date: Apr 14, 2026