Views
4

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

Update Summary

KB5087545 updates Windows Server 2022 to OS Build 20348.5139 with security fixes, quality improvements, and Secure Boot rollout changes. It also includes a servicing stack update, addresses Remote Desktop dialog rendering, and notes BitLocker and WSUS-related issues.

Update Details

Security

  • Adds additional high-confidence device targeting data to help eligible devices receive new Secure Boot certificates in a controlled rollout.
  • Introduces a new C:\Windows\SecureBoot folder on eligible devices with scripts for detecting Secure Boot certificate update status and automating deployment in Active Directory environments.
  • Addresses the Remote Desktop Connection security warning dialog rendering issue in multi-monitor scenarios with different scaling.
  • WSUS synchronization error details are temporarily removed to address the Remote Code Execution vulnerability CVE-2025-59287.

Bug Fixes

  • Improves calculation accuracy and reliability for apps and system components, especially with very small values.
  • Improves Windows Server interface responsiveness and reduces instances where windows stop responding.
  • Fixes the Remote Desktop Connection security warning dialog rendering incorrectly in multi-monitor scenarios with different scaling.

New Features

  • Adds a new C:\Windows\SecureBoot folder on eligible devices containing example scripts for Secure Boot certificate update management.
  • Supports the 2023 daylight saving time change for the Arab Republic of Egypt.

Known Issues

  • Some devices with an unrecommended BitLocker Group Policy configuration may be prompted for the BitLocker recovery key on the first restart after installing the update.
  • After installing KB5070884 or later updates, WSUS does not display synchronization error details in its error reporting.

Hints

  • Release date: 2026-05-12.
  • Includes fixes and quality improvements from KB5082142 and KB5091575.
  • If affected by the BitLocker issue, Microsoft recommends setting the BitLocker TPM platform validation profile policy to Not Configured, running gpupdate /force, then suspending and resuming BitLocker.
  • The servicing stack update is KB5089140 (OS Build 20348.5120).
  • The Secure Boot guidance references a phased rollout and sample automation for organizations managing device fleets.
Product Information

Vendor: Microsoft

Product: Windows Server 2022

Version: OS Build 20348.5139

Release date: May 12, 2026