August 9, 2022—KB5016683 (Security-only update)
Applies To
Windows 8.1 Windows RT 8.1 Windows Server 2012 R2 Windows Embedded 8.1 Industry Enterprise Windows Embedded 8.1 Industry ProRelease Date:
09/08/2022
Version:
Security-only update
IMPORTANT Microsoft released update KB5012170 on August 9, 2022. It provides support for Secure Boot Forbidden Signature Database (DBX). This is a standalone, security update. Windows 8.1 and newer clients and Windows Server 2012 and newer servers must install this update regardless of whether BitLocker is enabled or supported on your device. After you install the update, you might receive error “0x800f0922”; see Update might fail to install and you might receive a 0x800f0922 error. After you install the update, your device might start up in BitLocker recovery mode. See Some devices might start up into BitLocker Recovery and Finding your BitLocker recovery key in Windows.
Summary
Learn more about this security-only update, including improvements, any known issues, and how to get the update.
REMINDER Windows 8.1 will reach end of support on January 10, 2023, at which point technical assistance and software updates will no longer be provided. If you have devices running Windows 8.1, we recommend upgrading them to a more current, in-service, and supported Windows release. If devices do not meet the technical requirements to run a more current release of Windows, we recommend that you replace the device with one that supports Windows 11.
Microsoft will not be offering an Extended Security Update (ESU) program for Windows 8.1. Continuing to use Windows 8.1 after January 10, 2023 may increase an organization’s exposure to security risks or impact its ability to meet compliance obligations.
For more information, see Windows 8.1 support will end on January 10, 2023.
Windows Server 2012 R2 will reach end of support on October 10, 2023 for Datacenter, Essentials, Embedded Systems, Foundation, and Standard.
Improvements
This security-only update includes new improvements for the following issue:
-
Addresses an issue in which Speech and Network troubleshooters will not start.
-
Addresses an issue that might cause the Local Security Authority Server Service (LSASS) to leak tokens. This issue affects devices that have installed Windows updates dated June 14, 2022 or later. This issue occurs when the device performs a specific form of service for user (S4U) in a non-Trusted Computing Base (TCB) Windows service that runs as Network Service.
-
Enforces a hardening change that requires printers and scanners that use smart cards for authentication to have firmware that complies with section 3.2.1 of RFC 4556. If they do not comply, Active Directory domain controllers will not authenticate them. Mitigations that allowed non-compliant devices to authenticate will not exist after August 9, 2022. For more information about this change, see KB5005408.
For more information about the resolved security vulnerabilities, please refer to the Deployments | Security Update Guide and the August 2022 Security Updates.
Known issues in this update
Symptoms |
Next step |
Starting at 12:00 A.M. Saturday, September 10, 2022, the official time in Chile will advance 60 minutes in accordance with the August 9, 2022 official announcement by the Chilean government about a daylight saving time (DST) time zone change. This moves the DST change which was previously September 4 to September 10. Symptoms if the workaround is not used on devices between September 4, 2022 and September 11, 2022:
|
This issue is resolved in update KB5018476. |
How to get this update
Before installing this update
We strongly recommend that you install the latest servicing stack update (SSU) for your operating system before you install the latest Rollup. SSUs improve the reliability of the update process to mitigate potential issues while installing the Rollup and applying Microsoft security fixes. For general information about SSUs, see Servicing stack updates and Servicing Stack Updates (SSU): Frequently Asked Questions.
If you use Windows Update, the latest SSU (KB5016264) will be offered to you automatically. To get the standalone package for the latest SSU, search for it in the Microsoft Update Catalog.
REMINDER If you are using Security-only updates, you will also need to install all previous Security-only updates and the latest cumulative update for Internet Explorer (KB5016618).
Install this update
Release Channel |
Available |
Next Step |
Windows Update and Microsoft Update |
No |
See the other options below. |
Microsoft Update Catalog |
Yes |
To get the standalone package for this update, go to the Microsoft Update Catalog website. |
Windows Server Update Services (WSUS) |
Yes |
This update will automatically sync with WSUS if you configure Products and Classifications as follows: Product: Windows 8.1, Windows Server 2012 R2, Windows Embedded 8.1 Industry Enterprise, Windows Embedded 8.1 Industry Pro Classification: Security Update |
File information
For a list of the files that are provided in this update, download the file information for update KB5016683.
References
Learn about the standard terminology that is used to describe Microsoft software updates.