Views
3

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

Update Summary

KB5091157 is a non-security out-of-band update for Windows Server 2025, OS Build 26100.32698. It fixes Active Directory startup/authentication issues on some domain controllers and resolves failures installing KB5082063.

Update Details

Security

  • WSUS synchronization error details are temporarily removed to address the Remote Code Execution vulnerability CVE-2025-59287.

Bug Fixes

  • Fixed an Active Directory issue where some domain controllers in multi-domain forests using PAM could fail to start after the April 2026 security update, causing LSASS hangs, repeated restarts, and authentication/directory service outages.
  • Fixed an issue where some Windows Server 2025 devices could fail to install KB5082063 with errors 0x800F0983 or 0x80073712.
  • Fixed a Remote Desktop warning display issue where the security warning for opening RDP files could render incorrectly on multi-monitor setups with mixed scaling.
  • Servicing stack update KB5082062 improves the reliability of the Windows update installation component.

Known Issues

  • Devices with an unrecommended BitLocker Group Policy configuration might prompt for the BitLocker recovery key on the first restart after installing this update.
  • WSUS does not display synchronization error details after installing KB5070881 or later updates.
  • Remote Desktop security warnings might not display correctly in some multi-monitor scaling configurations.

Hints

  • If affected by the BitLocker issue, Microsoft recommends removing the PCR7 Group Policy setting before installing the update, then running gpupdate /force and suspending/resuming BitLocker protectors.
  • A Known Issue Rollback (KIR) is available for organizations that cannot remove the PCR7 policy before deployment.
  • If earlier updates are already installed, only the new updates in this package are downloaded and installed.
  • The Remote Desktop warning display issue is addressed in KB5087539.
Product Information

Vendor: Microsoft

Product: Windows Server 2025

Version: OS Build 26100.32698

Release date: Apr 19, 2026