Applies To
Windows Server, version 23H2

Windows Secure Boot certificate expiration 

Important: Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. This might affect the ability of certain personal and business devices to boot securely if not updated in time. To avoid disruption, we recommend reviewing the guidance and taking action to update certificates in advance. For details and preparation steps, see Windows Secure Boot certificate expiration and CA updates.

Summary

This update makes improvements to the Windows recovery environment (WinRE) in Windows Server, version 23H2.

How to get this update

Install this update

To install this update, use one of the following release channels.

Available

Next step

Available

This update is available through Windows Update. It will be downloaded and installed automatically.

Prerequisites

There are no prerequisites to apply this update.

Restart information

You do not have to restart your device after you apply this update.

Removal information

This update cannot be removed once it is applied to a Windows image.

Update replacement information

This update replaces the previously released update KB5060116.

Verify the installation of this update

After installing this update, the WinRE version installed on the device should be 10.0.25398.1733.

To get the version of WinRE installed, run the following PowerShell script "GetWinReVersion.ps1" with Administrator credentials. After you run the script, you should receive the installed WinRE version as in the following example:

GetWinReVersion.ps1 PowerShell script

################################################################################################

#

# Copyright (c) Microsoft Corporation.

# Licensed under the MIT License.

#

# THE SOFTWARE IS PROVIDED *AS IS*, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR

# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,

# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE

# AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER

# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

# OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE

# SOFTWARE.

#

################################################################################################
# Function to get WinRE path

function GetWinREPath {

    $WinRELocation = (reagentc /info | Select-String "Windows RE location")

    if ($WinRELocation) {

        return $WinRELocation.ToString().Split(':')[-1].Trim()

    } else {

        Write-Host "Failed to find WinRE path" -ForegroundColor Red

        exit 1

    }

}

 
# Creates and needs to be return the mount directory
function GetMountDir {
    # systemdirve\mnt
    $MountDir = "$env:SystemDrive\mnt"
    if (-not (Test-Path $MountDir)) {
        New-Item -ItemType Directory -Path $MountDir -Force | Out-Null
    }
    return $MountDir
}  

# Function to get WinRE version
function GetWinREVersion {

    $mountedPath = GetMountDir
    $filePath = "$mountedPath\Windows\System32\winpeshl.exe"

    $WinREVersion = (Get-Item $filePath).VersionInfo.FileVersionRaw.Revision

    return [int]$WinREVersion

}


# Main Execution

$WinREPath = GetWinREPath


# Make dir C:\mnt if not exists

$TempDir = GetMountDir


# Get the read write permission for this directory

if (-not (Test-Path $TempDir)) {

    New-Item -ItemType Directory -Path $TempDir -Force | Out-Null

}


# Mount WinRE image

dism /Mount-Image /ImageFile:"$WinREPath\winre.wim" /Index:1 /MountDir:"$TempDir"


$WinREVersion = GetWinREVersion

Write-Host "WinRE Version: $WinREVersion" -ForegroundColor Cyan

dism /Unmount-Image /MountDir:"$TempDir" /Discard

Remove-Item -Path $TempDir -Force -Recurse

File information

The English (United States) version of this software update installs files that have the following attributes. This update might contain files for additional languages.

File name

File version

Date

Time

File size

skci.dll

10.0.25398.1733

4-Jul-25

23:55

336,176

iumbase.dll

10.0.25398.1733

4-Jul-25

23:55

46,968

iumdll.dll

10.0.25398.1733

4-Jul-25

23:55

38,720

tprtdll.dll

10.0.25398.1733

4-Jul-25

23:55

249,432

vertdll.dll

10.0.25398.1733

4-Jul-25

23:55

212,248

ucrtbase_enclave.dll

10.0.25398.1733

4-Jul-25

23:55

546,912

securekernel.exe

10.0.25398.1733

4-Jul-25

23:55

1,226,144

VbsSiPolicy.p7b

Not versioned

4-Jul-25

23:55

68,351

bootmgfw.efi

10.0.25398.1733

4-Jul-25

23:55

2,654,128

bootmgfw_EX.efi

10.0.26100.30212

4-Jul-25

23:55

2,830,632

SecureBootRecovery.efi

Not versioned

4-Jul-25

23:55

162,688

bootmgr.efi

10.0.25398.1733

4-Jul-25

23:55

2,637,752

bootmgr_EX.efi

10.0.26100.30212

4-Jul-25

23:55

2,818,464

boot.stl

Not versioned

4-Jul-25

23:55

11,030

winsipolicy.p7b

Not versioned

4-Jul-25

23:55

10,341

winload.exe

10.0.25398.1733

4-Jul-25

23:55

1,715,440

winload.efi

10.0.25398.1733

4-Jul-25

23:55

3,072,312

BootMenuUX.dll

10.0.25398.1733

4-Jul-25

23:55

229,376

driversipolicy.p7b

Not versioned

4-Jul-25

23:55

229,162

ci.dll

10.0.25398.1733

4-Jul-25

23:55

1,059,280

driver.stl

Not versioned

4-Jul-25

23:55

32,631

cmi2migxml.dll

10.0.25398.1733

4-Jul-25

23:55

222,640

csiagent.dll

10.0.25398.1733

4-Jul-25

23:55

714,184

diagER.dll

10.0.25398.1733

4-Jul-25

23:55

95,688

hwcompat.dll

10.0.25398.1733

4-Jul-25

23:55

239,032

hwcompat.txt

Not versioned

4-Jul-25

23:55

969,192

hwexclude.txt

Not versioned

4-Jul-25

23:55

51

icbexclusion.inf

Not versioned

4-Jul-25

23:55

7,222

migapp.xml

Not versioned

4-Jul-25

23:55

654,548

migcore.dll

10.0.25398.1733

4-Jul-25

23:55

9,270,688

mighost.exe

10.0.25398.1733

4-Jul-25

23:55

284,088

migres.dll

10.0.25398.1733

4-Jul-25

23:55

26,040

migisol.dll

10.0.25398.1733

4-Jul-25

23:55

144,824

migstore.dll

10.0.25398.1733

4-Jul-25

23:55

1,295,800

migsys.dll

10.0.25398.1733

4-Jul-25

23:55

460,216

MXEAgent.dll

10.0.25398.1733

4-Jul-25

23:55

386,488

AppExtAgent.dll

10.0.25398.1733

4-Jul-25

23:55

484,792

offline.xml

Not versioned

4-Jul-25

23:55

41,994

oscomps.xml

Not versioned

4-Jul-25

23:55

449,323

oscomps.woa.xml

Not versioned

4-Jul-25

23:55

249,101

osfilter.inf

Not versioned

4-Jul-25

23:55

21,299

pnppropmig.dll

10.0.25398.1733

4-Jul-25

23:55

103,840

ReserveManager.dll

10.0.25398.1733

4-Jul-25

23:55

308,640

setupplatform.cfg

Not versioned

4-Jul-25

23:55

12,571

setupplatform.dll

1.80.25398.1733

4-Jul-25

23:55

9,213,368

setupplatform.exe

1.80.25398.1733

4-Jul-25

23:55

243,144

SFCN.dat

Not versioned

4-Jul-25

23:55

1,824

SFLCID.dat

Not versioned

4-Jul-25

23:55

1,644

SFLISTW7.dat

Not versioned

4-Jul-25

23:55

1,703,368

SFLISTW8.dat

Not versioned

4-Jul-25

23:55

2,608,858

SFLISTWB.dat

Not versioned

4-Jul-25

23:55

3,172,904

SFLISTWT.dat

Not versioned

4-Jul-25

23:55

4,935,402

sflistw8.woa.dat

Not versioned

4-Jul-25

23:55

954,436

SFLISTRS1.dat

Not versioned

4-Jul-25

23:55

5,593,182

sflistwb.woa.dat

Not versioned

4-Jul-25

23:55

1,150,134

sflistwt.woa.dat

Not versioned

4-Jul-25

23:55

2,636,814

SFPAT.inf

Not versioned

4-Jul-25

23:55

11,602

SFPATW7.inf

Not versioned

4-Jul-25

23:55

17,396

SFPATW8.inf

Not versioned

4-Jul-25

23:55

79,818

SFPATWB.inf

Not versioned

4-Jul-25

23:55

91,635

SFPATWT.inf

Not versioned

4-Jul-25

23:55

165,729

SFPATRS1.inf

Not versioned

4-Jul-25

23:55

169,730

unbcl.dll

10.0.25398.1733

4-Jul-25

23:55

1,082,824

upgradeagent.dll

10.0.25398.1733

4-Jul-25

23:55

3,306,912

upgradeagent.xml

Not versioned

4-Jul-25

23:55

70,907

upgrade_comp.xml

Not versioned

4-Jul-25

23:55

6,054

upgrade_bulk.xml

Not versioned

4-Jul-25

23:55

211,085

upgrade_data.xml

Not versioned

4-Jul-25

23:55

41,750

upgrade_frmwrk.xml

Not versioned

4-Jul-25

23:55

18,785

upgWow_bulk.xml

Not versioned

4-Jul-25

23:55

114,707

uninstall.xml

Not versioned

4-Jul-25

23:55

4,639

uninstall_data.xml

Not versioned

4-Jul-25

23:55

11,122

wdsutil.dll

10.0.25398.1733

4-Jul-25

23:55

349,640

WinSetupMon.hiv

Not versioned

4-Jul-25

23:55

8,192

WinSetupMon.sys

10.0.25398.1733

4-Jul-25

23:55

132,576

netio.sys

10.0.25398.1733

4-Jul-25

23:55

669,112

ntdll.dll

10.0.25398.1733

4-Jul-25

23:55

2,265,848

ntoskrnl.exe

10.0.25398.1733

4-Jul-25

23:55

12,690,888

ntkrla57.exe

10.0.25398.1733

4-Jul-25

23:55

11,449,776

diagtrack.dll

10.0.10586.0

4-Jul-25

23:55

1,365,856

diagtrackrunner.exe

10.0.10586.0

4-Jul-25

23:55

88,256

reagent.admx

Not versioned

4-Jul-25

23:55

1,240

reagent.dll

10.0.25398.1733

4-Jul-25

23:55

619,960

reagent.xml

Not versioned

4-Jul-25

23:55

837

SetupPlatform.cfg

Not versioned

4-Jul-25

23:55

19,051

wdscore.dll

10.0.25398.1733

4-Jul-25

23:55

275,872

wdsclientapi.dll

10.0.25398.1733

4-Jul-25

23:55

268,664

wdscsl.dll

10.0.25398.1733

4-Jul-25

23:55

79,288

wdsimage.dll

10.0.25398.1733

4-Jul-25

23:55

125,328

wdstptc.dll

10.0.25398.1733

4-Jul-25

23:55

186,744

fvevol.sys

10.0.25398.1733

4-Jul-25

23:55

898,464

dumpfve.sys

10.0.25398.1733

4-Jul-25

23:55

146,112

fveapibase.dll

10.0.25398.1733

4-Jul-25

23:55

507,904

fveapi.dll

10.0.25398.1733

4-Jul-25

23:55

1,097,728

tcpip.sys

10.0.25398.1733

4-Jul-25

23:55

3,319,240

FWPKCLNT.SYS

10.0.25398.1733

4-Jul-25

23:55

570,784

tcpipreg.sys

10.0.25398.1733

4-Jul-25

23:55

81,920

tcpip.sys.mui

10.0.25398.1733

4-Jul-25

23:55

233,472

tcpip.sys.mui

10.0.25398.1733

4-Jul-25

23:55

234,496

tcpip.sys.mui

10.0.25398.1733

4-Jul-25

23:55

228,864

tcpip.sys.mui

10.0.25398.1733

4-Jul-25

23:55

235,008

tcpip.sys.mui

10.0.25398.1733

4-Jul-25

23:55

236,544

tcpip.sys.mui

10.0.25398.1733

4-Jul-25

23:55

232,448

tcpip.sys.mui

10.0.25398.1733

4-Jul-25

23:55

219,648

tcpip.sys.mui

10.0.25398.1733

4-Jul-25

23:55

218,112

tcpip.sys.mui

10.0.25398.1733

4-Jul-25

23:55

232,960

tcpip.sys.mui

10.0.25398.1733

4-Jul-25

23:55

230,912

tcpip.sys.mui

10.0.25398.1733

4-Jul-25

23:55

215,040

winpeshl.exe

10.0.25398.1733

4-Jul-25

23:55

53,248

wpeutil.dll

10.0.25398.1733

4-Jul-25

23:55

155,648

wpeutil.exe

10.0.25398.1733

4-Jul-25

23:55

36,864

wpeinit.exe

10.0.25398.1733

4-Jul-25

23:55

57,344

startnet.cmd

Not versioned

4-Jul-25

23:55

9

ReInfo.dll

10.0.25398.1733

4-Jul-25

23:55

98,304

StartRep.exe

10.0.25398.1733

4-Jul-25

23:55

679,936

RecEnv.exe

10.0.25398.1733

4-Jul-25

23:55

415,160

BootRec.exe

10.0.25398.1733

4-Jul-25

23:55

192,512

ntdll.dll

10.0.25398.1733

4-Jul-25

23:55

1,747,488

fveapibase.dll

10.0.25398.1733

4-Jul-25

23:55

426,496

fveapi.dll

10.0.25398.1733

4-Jul-25

23:55

883,712

ReAgent.dll

10.0.25398.1733

4-Jul-25

23:55

529,840

ReInfo.dll

10.0.25398.1733

4-Jul-25

23:55

62,976

wdsnbp.com

Not versioned

4-Jul-25

23:55

30,832

abortpxe.com

Not versioned

4-Jul-25

23:55

79

bootmgr.exe

10.0.25398.1733

4-Jul-25

23:55

742,816

pxeboot.com

Not versioned

4-Jul-25

23:55

25,254

pxeboot.n12

Not versioned

4-Jul-25

23:55

25,238

hdlscom1.com

Not versioned

4-Jul-25

23:55

25,662

hdlscom2.com

Not versioned

4-Jul-25

23:55

25,662

hdlscom1.n12

Not versioned

4-Jul-25

23:55

25,646

hdlscom2.n12

Not versioned

4-Jul-25

23:55

25,646

bootmgfw.efi

10.0.25398.1733

4-Jul-25

23:55

2,240,440

bootmgfw_EX.efi

10.0.26100.30212

4-Jul-25

23:55

2,376,464

References

Description of the standard terminology that is used to describe Microsoft software updates

Query words: safeos du

Need more help?

Want more options?

Explore subscription benefits, browse training courses, learn how to secure your device, and more.