Applies To
Windows Server, version 23H2

Windows Secure Boot certificate expiration 

Important: Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. This might affect the ability of certain personal and business devices to boot securely if not updated in time. To avoid disruption, we recommend reviewing the guidance and taking action to update certificates in advance. For details and preparation steps, see Windows Secure Boot certificate expiration and CA updates.

Summary

This update makes improvements to the Windows recovery environment (WinRE).

How to get this update

Install this update

To install this update, use one of the following release channels.

Available

Next step

Available

This update is available through Windows Update. It will be downloaded and installed automatically.

Prerequisites

There are no prerequisites to apply this update.

Restart information

You do not have to restart your device after you apply this update.

Removal information

This update cannot be removed once it is applied to a Windows image.

Update replacement information

This update replaces the previously released update KB5068788.

Verify the installation of this update

After installing this update, the WinRE version installed on the device should be 10.0.25398.2021.

To get the version of WinRE installed, run the following PowerShell script "GetWinReVersion.ps1" with Administrator credentials. After you run the script, you should receive the installed WinRE version as in the following example:

GetWinReVersion.ps1 PowerShell script

################################################################################################

#

# Copyright (c) Microsoft Corporation.

# Licensed under the MIT License.

#

# THE SOFTWARE IS PROVIDED *AS IS*, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR

# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,

# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE

# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER

# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

# OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE

# SOFTWARE.

#

################################################################################################
# Function to get WinRE path

function GetWinREPath {

    $WinRELocation = (reagentc /info | Select-String "Windows RE location")

    if ($WinRELocation) {

        return $WinRELocation.ToString().Split(':')[-1].Trim()

    } else {

        Write-Host "Failed to find WinRE path" -ForegroundColor Red

        exit 1

    }

}

 
# Creates and needs to be return the mount directory
function GetMountDir {
    # systemdirve\mnt
    $MountDir = "$env:SystemDrive\mnt"
    if (-not (Test-Path $MountDir)) {
        New-Item -ItemType Directory -Path $MountDir -Force | Out-Null
    }
    return $MountDir
}  

# Function to get WinRE version
function GetWinREVersion {

    $mountedPath = GetMountDir
    $filePath = "$mountedPath\Windows\System32\winpeshl.exe"

    $WinREVersion = (Get-Item $filePath).VersionInfo.FileVersionRaw.Revision

    return [int]$WinREVersion

}


# Main Execution

$WinREPath = GetWinREPath


# Make dir C:\mnt if not exists

$TempDir = GetMountDir


# Get the read write permission for this directory

if (-not (Test-Path $TempDir)) {

    New-Item -ItemType Directory -Path $TempDir -Force | Out-Null

}


# Mount WinRE image

dism /Mount-Image /ImageFile:"$WinREPath\winre.wim" /Index:1 /MountDir:"$TempDir"


$WinREVersion = GetWinREVersion

Write-Host "WinRE Version: $WinREVersion" -ForegroundColor Cyan

dism /Unmount-Image /MountDir:"$TempDir" /Discard

Remove-Item -Path $TempDir -Force -Recurse

File information

The English (United States) version of this software update installs files that have the following attributes. This update might contain files for additional languages.

File name

File version

Date

Time

File size

usb.inf

Not versioned

14-Nov-25

19:09

41,432

usbccgp.sys

10.0.25398.2021

14-Nov-25

19:09

226,720

usbhub3.inf

Not versioned

14-Nov-25

19:09

11,296

USBHUB3.SYS

10.0.25398.2021

14-Nov-25

19:09

722,336

usbport.inf

Not versioned

14-Nov-25

19:09

77,436

usbohci.sys

10.0.25398.2021

14-Nov-25

19:09

69,632

usbport.sys

10.0.25398.2021

14-Nov-25

19:09

505,248

usbhub.sys

10.0.25398.2021

14-Nov-25

19:09

558,536

usbehci.sys

10.0.25398.2021

14-Nov-25

19:09

120,264

usbuhci.sys

10.0.25398.2021

14-Nov-25

19:09

73,728

usbd.sys

10.0.25398.2021

14-Nov-25

19:09

71,072

skci.dll

10.0.25398.2021

14-Nov-25

19:09

336,160

iumbase.dll

10.0.25398.2021

14-Nov-25

19:09

46,984

iumdll.dll

10.0.25398.2021

14-Nov-25

19:09

38,680

tprtdll.dll

10.0.25398.2021

14-Nov-25

19:09

249,408

vertdll.dll

10.0.25398.2021

14-Nov-25

19:09

212,216

ucrtbase_enclave.dll

10.0.25398.2021

14-Nov-25

19:09

546,912

securekernel.exe

10.0.25398.2021

14-Nov-25

19:09

1,226,144

VbsSiPolicy.p7b

Not versioned

14-Nov-25

19:09

68,351

bootmgfw.efi

10.0.25398.2021

14-Nov-25

19:09

2,658,760

bootmgfw_EX.efi

10.0.26100.30212

14-Nov-25

19:09

2,830,632

SecureBootRecovery.efi

Not versioned

14-Nov-25

19:09

162,688

bootmgr.efi

10.0.25398.2021

14-Nov-25

19:09

2,641,824

bootmgr_EX.efi

10.0.26100.30212

14-Nov-25

19:09

2,818,464

boot.stl

Not versioned

14-Nov-25

19:09

11,030

winsipolicy.p7b

Not versioned

14-Nov-25

19:09

10,341

winload.exe

10.0.25398.2021

14-Nov-25

19:09

1,718,544

winload.efi

10.0.25398.2021

14-Nov-25

19:09

3,077,536

BootMenuUX.dll

10.0.25398.2021

14-Nov-25

19:09

225,280

driversipolicy.p7b

Not versioned

14-Nov-25

19:09

229,162

ci.dll

10.0.25398.2021

14-Nov-25

19:09

1,059,256

driver.stl

Not versioned

14-Nov-25

19:09

33,360

cmi2migxml.dll

10.0.25398.2021

14-Nov-25

19:09

222,664

csiagent.dll

10.0.25398.2021

14-Nov-25

19:09

714,184

diagER.dll

10.0.25398.2021

14-Nov-25

19:09

95,648

hwcompat.dll

10.0.25398.2021

14-Nov-25

19:09

239,048

hwcompat.txt

Not versioned

14-Nov-25

19:09

969,192

hwexclude.txt

Not versioned

14-Nov-25

19:09

51

icbexclusion.inf

Not versioned

14-Nov-25

19:09

7,222

migapp.xml

Not versioned

14-Nov-25

19:09

654,548

migcore.dll

10.0.25398.2021

14-Nov-25

19:09

9,270,688

mighost.exe

10.0.25398.2021

14-Nov-25

19:09

284,064

migres.dll

10.0.25398.2021

14-Nov-25

19:09

26,016

migisol.dll

10.0.25398.2021

14-Nov-25

19:09

144,840

migstore.dll

10.0.25398.2021

14-Nov-25

19:09

1,295,776

migsys.dll

10.0.25398.2021

14-Nov-25

19:09

460,192

MXEAgent.dll

10.0.25398.2021

14-Nov-25

19:09

386,464

AppExtAgent.dll

10.0.25398.2021

14-Nov-25

19:09

484,768

offline.xml

Not versioned

14-Nov-25

19:09

41,994

oscomps.xml

Not versioned

14-Nov-25

19:09

449,323

oscomps.woa.xml

Not versioned

14-Nov-25

19:09

249,101

osfilter.inf

Not versioned

14-Nov-25

19:09

21,299

pnppropmig.dll

10.0.25398.2021

14-Nov-25

19:09

103,840

ReserveManager.dll

10.0.25398.2021

14-Nov-25

19:09

308,640

setupplatform.cfg

Not versioned

14-Nov-25

19:09

12,571

setupplatform.dll

1.80.25398.2021

14-Nov-25

19:09

9,213,344

setupplatform.exe

1.80.25398.2021

14-Nov-25

19:09

243,104

SFCN.dat

Not versioned

14-Nov-25

19:09

1,824

SFLCID.dat

Not versioned

14-Nov-25

19:09

1,644

SFLISTW7.dat

Not versioned

14-Nov-25

19:09

1,703,368

SFLISTW8.dat

Not versioned

14-Nov-25

19:09

2,608,858

SFLISTWB.dat

Not versioned

14-Nov-25

19:09

3,172,904

SFLISTWT.dat

Not versioned

14-Nov-25

19:09

4,935,402

sflistw8.woa.dat

Not versioned

14-Nov-25

19:09

954,436

SFLISTRS1.dat

Not versioned

14-Nov-25

19:09

5,593,182

sflistwb.woa.dat

Not versioned

14-Nov-25

19:09

1,150,134

sflistwt.woa.dat

Not versioned

14-Nov-25

19:09

2,636,814

SFPAT.inf

Not versioned

14-Nov-25

19:09

11,602

SFPATW7.inf

Not versioned

14-Nov-25

19:09

17,396

SFPATW8.inf

Not versioned

14-Nov-25

19:09

79,818

SFPATWB.inf

Not versioned

14-Nov-25

19:09

91,635

SFPATWT.inf

Not versioned

14-Nov-25

19:09

165,729

SFPATRS1.inf

Not versioned

14-Nov-25

19:09

169,730

unbcl.dll

10.0.25398.2021

14-Nov-25

19:09

1,082,784

upgradeagent.dll

10.0.25398.2021

14-Nov-25

19:09

3,306,952

upgradeagent.xml

Not versioned

14-Nov-25

19:09

70,907

upgrade_comp.xml

Not versioned

14-Nov-25

19:09

6,054

upgrade_bulk.xml

Not versioned

14-Nov-25

19:09

211,085

upgrade_data.xml

Not versioned

14-Nov-25

19:09

41,750

upgrade_frmwrk.xml

Not versioned

14-Nov-25

19:09

18,785

upgWow_bulk.xml

Not versioned

14-Nov-25

19:09

114,707

uninstall.xml

Not versioned

14-Nov-25

19:09

4,639

uninstall_data.xml

Not versioned

14-Nov-25

19:09

11,122

wdsutil.dll

10.0.25398.2021

14-Nov-25

19:09

349,600

WinSetupMon.hiv

Not versioned

14-Nov-25

19:09

8,192

WinSetupMon.sys

10.0.25398.2021

14-Nov-25

19:09

132,528

iertutil.dll

11.0.25398.2021

14-Nov-25

19:09

2,864,936

msIso.dll

11.0.25398.2021

14-Nov-25

19:09

278,528

edgeIso.dll

11.0.25398.2021

14-Nov-25

19:09

434,176

dxgkrnl.sys

10.0.25398.2021

14-Nov-25

19:09

4,863,392

cdd.dll

10.0.25398.2021

14-Nov-25

19:09

311,296

dxgmms1.sys

10.0.25398.2021

14-Nov-25

19:09

529,864

dxgmms2.sys

10.0.25398.2021

14-Nov-25

19:09

1,168,800

dxgkrnl.sys.mui

10.0.25398.2021

14-Nov-25

19:09

114,176

dxgmms2.sys.mui

10.0.25398.2021

14-Nov-25

19:09

5,120

dxgkrnl.sys.mui

10.0.25398.2021

14-Nov-25

19:09

115,200

dxgmms2.sys.mui

10.0.25398.2021

14-Nov-25

19:09

5,632

dxgkrnl.sys.mui

10.0.25398.2021

14-Nov-25

19:09

115,712

dxgkrnl.sys.mui

10.0.25398.2021

14-Nov-25

19:09

112,640

dxgmms2.sys.mui

10.0.25398.2021

14-Nov-25

19:09

4,608

dxgkrnl.sys.mui

10.0.25398.2021

14-Nov-25

19:09

112,128

dxgkrnl.sys.mui

10.0.25398.2021

14-Nov-25

19:09

111,616

netio.sys

10.0.25398.2021

14-Nov-25

19:09

669,128

ntdll.dll

10.0.25398.2021

14-Nov-25

19:09

2,265,824

ntoskrnl.exe

10.0.25398.2021

14-Nov-25

19:09

12,694,944

ntkrla57.exe

10.0.25398.2021

14-Nov-25

19:09

11,457,952

diagtrack.dll

10.0.10586.0

14-Nov-25

19:09

1,365,856

diagtrackrunner.exe

10.0.10586.0

14-Nov-25

19:09

88,256

reagent.admx

Not versioned

14-Nov-25

19:09

1,240

reagent.dll

10.0.25398.2021

14-Nov-25

19:09

615,880

reagent.xml

Not versioned

14-Nov-25

19:09

837

SetupPlatform.cfg

Not versioned

14-Nov-25

19:09

19,051

wdscore.dll

10.0.25398.2021

14-Nov-25

19:09

275,912

wdsclientapi.dll

10.0.25398.2021

14-Nov-25

19:09

268,704

wdscsl.dll

10.0.25398.2021

14-Nov-25

19:09

79,264

wdsimage.dll

10.0.25398.2021

14-Nov-25

19:09

125,304

wdstptc.dll

10.0.25398.2021

14-Nov-25

19:09

186,784

fvevol.sys

10.0.25398.2021

14-Nov-25

19:09

898,504

dumpfve.sys

10.0.25398.2021

14-Nov-25

19:09

146,088

fveapibase.dll

10.0.25398.2021

14-Nov-25

19:09

507,904

fveapi.dll

10.0.25398.2021

14-Nov-25

19:09

1,097,728

tcpip.sys

10.0.25398.2021

14-Nov-25

19:09

3,319,200

FWPKCLNT.SYS

10.0.25398.2021

14-Nov-25

19:09

570,824

tcpipreg.sys

10.0.25398.2021

14-Nov-25

19:09

81,920

tcpip.sys.mui

10.0.25398.2021

14-Nov-25

19:09

233,472

tcpip.sys.mui

10.0.25398.2021

14-Nov-25

19:09

234,496

tcpip.sys.mui

10.0.25398.2021

14-Nov-25

19:09

228,864

tcpip.sys.mui

10.0.25398.2021

14-Nov-25

19:09

235,008

tcpip.sys.mui

10.0.25398.2021

14-Nov-25

19:09

236,544

tcpip.sys.mui

10.0.25398.2021

14-Nov-25

19:09

232,448

tcpip.sys.mui

10.0.25398.2021

14-Nov-25

19:09

219,648

tcpip.sys.mui

10.0.25398.2021

14-Nov-25

19:09

218,112

tcpip.sys.mui

10.0.25398.2021

14-Nov-25

19:09

232,960

tcpip.sys.mui

10.0.25398.2021

14-Nov-25

19:09

230,912

tcpip.sys.mui

10.0.25398.2021

14-Nov-25

19:09

215,040

win32u.dll

10.0.25398.2021

14-Nov-25

19:09

170,944

win32k.sys

10.0.25398.2021

14-Nov-25

19:09

704,512

win32kfull.sys

10.0.25398.2021

14-Nov-25

19:09

4,177,920

win32kbase.sys

10.0.25398.2021

14-Nov-25

19:09

3,379,200

win32kbase.sys.mui

10.0.25398.2021

14-Nov-25

19:09

22,016

win32kbase.sys.mui

10.0.25398.2021

14-Nov-25

19:09

23,552

win32kbase.sys.mui

10.0.25398.2021

14-Nov-25

19:09

21,504

win32kbase.sys.mui

10.0.25398.2021

14-Nov-25

19:09

24,064

win32kbase.sys.mui

10.0.25398.2021

14-Nov-25

19:09

23,040

win32kbase.sys.mui

10.0.25398.2021

14-Nov-25

19:09

18,432

win32kbase.sys.mui

10.0.25398.2021

14-Nov-25

19:09

17,920

win32kbase.sys.mui

10.0.25398.2021

14-Nov-25

19:09

15,872

win32kbase.sys.mui

10.0.25398.2021

14-Nov-25

19:09

16,384

win32ksgd.sys

10.0.25398.2021

14-Nov-25

19:09

98,304

WindowsCodecs.dll

10.0.25398.2021

14-Nov-25

19:09

2,224,520

winpeshl.exe

10.0.25398.2021

14-Nov-25

19:09

90,112

wpeutil.dll

10.0.25398.2021

14-Nov-25

19:09

155,648

wpeutil.exe

10.0.25398.2021

14-Nov-25

19:09

36,864

wpeinit.exe

10.0.25398.2021

14-Nov-25

19:09

57,344

startnet.cmd

Not versioned

14-Nov-25

19:09

9

ReInfo.dll

10.0.25398.2021

14-Nov-25

19:09

61,440

StartRep.exe

10.0.25398.2021

14-Nov-25

19:09

663,552

RecEnv.exe

10.0.25398.2021

14-Nov-25

19:09

415,136

BootRec.exe

10.0.25398.2021

14-Nov-25

19:09

180,224

iertutil.dll

11.0.25398.2021

14-Nov-25

19:09

2,320,760

msIso.dll

11.0.25398.2021

14-Nov-25

19:09

205,824

edgeIso.dll

11.0.25398.2021

14-Nov-25

19:09

373,248

ntdll.dll

10.0.25398.2021

14-Nov-25

19:09

1,749,032

fveapibase.dll

10.0.25398.2021

14-Nov-25

19:09

426,496

fveapi.dll

10.0.25398.2021

14-Nov-25

19:09

883,712

WindowsCodecs.dll

10.0.25398.2021

14-Nov-25

19:09

1,931,760

ReAgent.dll

10.0.25398.2021

14-Nov-25

19:09

524,704

ReInfo.dll

10.0.25398.2021

14-Nov-25

19:09

30,720

wdsnbp.com

Not versioned

14-Nov-25

19:09

30,832

abortpxe.com

Not versioned

14-Nov-25

19:09

79

bootmgr.exe

10.0.25398.2021

14-Nov-25

19:09

742,856

pxeboot.com

Not versioned

14-Nov-25

19:09

25,254

pxeboot.n12

Not versioned

14-Nov-25

19:09

25,238

hdlscom1.com

Not versioned

14-Nov-25

19:09

25,662

hdlscom2.com

Not versioned

14-Nov-25

19:09

25,662

hdlscom1.n12

Not versioned

14-Nov-25

19:09

25,646

hdlscom2.n12

Not versioned

14-Nov-25

19:09

25,646

bootmgfw.efi

10.0.25398.2021

14-Nov-25

19:09

2,242,464

bootmgfw_EX.efi

10.0.26100.30212

14-Nov-25

19:09

2,376,464

References

Description of the standard terminology that is used to describe Microsoft software updates

Query words: safeos du

Need more help?

Want more options?

Explore subscription benefits, browse training courses, learn how to secure your device, and more.