Support for Windows Server 2008 will end in January 2026
Windows Server 2008 Premium Assurance will end on January 13, 2026.
Windows Server 2008 Extended Security Updates (ESU) ended on January 10, 2023. Additionally, Extended Security Updates on Azure only support ended on January 9, 2024. For more information, see Extended Security Updates for Windows Server overview.
We recommend that you upgrade to a later version of Windows Server. For more information, see Overview of Windows Server upgrades.
Summary
Learn more about this security-only update, including improvements, any known issues, and how to get the update.
Verify that you have installed the required updates in the How to get this update section before installing this update.
For information about the various types of Windows updates, such as critical, security, driver, service packs, and so on, see Description of the standard terminology that is used to describe Microsoft software updates. To view other notes and messages for Windows Server 2008 SP2, see Windows Server 2008 SP2 update history.
Improvements
The following is a summary of the key issues that this update addresses. The bold text within the brackets indicates the item or area of the change we are documenting.
-
[Use-after-free (UAF) risk] Fixed: A race condition might lead to a UAF risk during process creation.
-
[Daylight saving time (DST)] This update supports DST changes in Paraguay. For more information, see the Daylight Saving Time & Time Zone Blog.
For more information about the resolved security vulnerabilities, please refer to the Deployments | Security Update Guide and the March 2025 Security Updates.
Known issues in this update
Symptom |
Next step |
After installing this update and restarting your device, you might receive the error, “Failure to configure Windows updates. Reverting Changes. Do not turn off your computer”, and the update might show as Failed in Update History. |
This is expected in the following circumstances:
If you have an ESU key and have encountered this issue, please verify you have applied all prerequisites and that your key is activated. For information on activation, see the Obtaining Extended Security Updates for eligible Windows devices blog post. For information on the prerequisites, see the How to get this update section of this article. |
For the most up-to-date information about known issues for Windows Server 2008 SP2, please go to the Windows release health dashboard.
How to get this update
Before installing this update
To install any Windows Server 2008 SP2 Security-only update released on or after January 14, 2025, you must first install the latest Servicing Stack Update (SSU). If your device or offline image does not have the latest SSU installed, you cannot install this update.
Caution: Until you install the SSU, this update will not be offered to your device. To reduce your security risk, install the SSU as soon as possible.
-
If you use Windows Update, the latest SSU (KB5050682) will be offered to you automatically. After the latest SSU is installed, you will be able to install this update.
-
If you use the Update Catalog, you must download and install the latest SSU (KB5050682). After the latest SSU is installed, you will be able to install this update.
-
If you are a Windows Server Update Services (WSUS) administrator, you must approve SSU KB5050682 and this update KB5053995.
For general information about SSUs, see Servicing stack updates and Servicing Stack Updates (SSU): Frequently Asked Questions.
Language packs
If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Learn about adding a language pack to Windows.
Install this update
To install this update, use one of the following release channels.
Available |
Next step |
|
This update is not available from Windows Update. See the Update Catalog or Server Update Services release channel. |
Available |
Next step |
|
To get the standalone package for this update, go to the Microsoft Update Catalog website. To download updates from the Update Catalog, see Steps to download updates from the Windows Update Catalog. |
Available |
Next step |
|
This update will automatically sync with Windows Server Update Services (WSUS) if you configure Products and Classifications as follows:
|
Reminder If you are using Security-only updates, you will also need to install all previous Security-only updates and the latest cumulative update for Internet Explorer (KB5053593).
File information
A list of the files that are included in this update are provided in a CSV (Comma delimited) (*.csv) file. The file can be opened in a text editor such as Notepad or in Microsoft Excel.