Flexis June 2024 Patch Recommendation

Patches Microsoft released in June 2024:

 

  • KB5039227: – 2024-06 Cumulative Update for Microsoft server operating system version 21H2 for x64-based Systems
  • KB5039217: – 2024-06 Cumulative Update for Windows Server 2016 for x64-based Systems
  • KB5039214: – 2024-06 Cumulative Update for Windows Server 2016 for x64-based Systems

Impacted Products:

Microsoft Windows

Microsoft Edge

(HTML-based)

Microsoft Edge

 (Chromium-based)

Internet Explorer

Microsoft Office and Microsoft Office Services and Web Apps

Windows Defender

Visual Studio

ASP.NET Core

Chakra Core

Microsoft Dynamics

.NET Framework

.NET Core

Please note the following information regarding the security updates:

Windows 10 Enterprise and Education and Windows 10 Home and Pro lifecycle pages, Windows 10 will reach end of support on October 14, 2025. The current version, 22H2, will be the final version of Windows 10. The following editions will remain in support with monthly security update releases through that date:

Home

Pro

Pro Education

Pro for Workstations

Education

Enterprise

Enterprise multi-session

KB5039227: Windows Server 2022

Improvements

New! This update affects Server Message Block (SMB) over Quick UDP Internet Connections (QUIC). It turns on the SMB over QUIC client certificate authentication feature. Admins can use it to restrict which clients can access SMB over QUIC servers. To learn more, see Configure SMB over QUIC client access control in Windows Server.

New! The LCU will no longer have the reverse differentials. The client will generate the playback delta. This change will help to reduce the LCU package size by about 20%. This change also offers a few advantages. It:

Reduces bandwidth usage

Provides faster downloads

Minimizes network traffic

Improves performance on slow connections.

This update affects the version of curl.exe that isin Windows. The version number is now 8.7.1.

This update addresses an issue that affects Outlook and OneNote. Their search function stops working. This occurs when you use Azure Virtual Desktop (AVD).

This update addresses an issue that affects lsass.exe. It stops responding. This occurs after you install the April 2024 security updates on Windows servers.

This update addresses an issue that affects Windows Hello for Business. You cannot use it to authenticate to Entra ID on certain apps. This occurs when you use Web Access Management (WAM).

This update addresses an issue that affects a Microsoft Entra ID account. Devices cannot authenticate a second one. This occurs after you install the Windows update, dated November 13, 2023.

This update addresses an issue that affects Microsoft Edge. The UI is wrong for the Internet Options Data Settings.

This update addresses an issue that affects Storage Spaces Direct (S2D) and Remote Direct Memory Access (RDMA). When you use them with SMBdirect in your networks, the networks fail. You also lose the ability to manage clusters.

This update addresses an issue that affects Containers. They do not move past the “ContainerCreating” status.

This update addresses an issue that might stop your system from resuming from hibernate. This occurs after you turn on BitLocker.

This update addresses an issue that affects Windows Defender Application Control (WDAC). The issue copies unsigned WDAC policies to the Extensible Firmware Interface (EFI) disk partition. It is reserved for signed policies.

This update addresses an issue that affects Enhanced Fast Reconnect. It fails. This occurs when you use it with third-party remote desktop protocol (RDP) providers.

This update addresses an issue that affects the Remote Desktop Session Host (RD Session Host). A deadlock occurs when a large number of users sign in.

This update addresses an issue that affects dsamain.exe. It stops responding. This occurs when the Knowledge Consistency Checker (KCC) runs evaluations.

This update addresses an issue that affects lsass.exe. It leaks memory. This occurs during a Local Security Authority (Domain Policy) Remote Protocol (LSARPC) call.

This update addresses an issue that affects the kernel stack. It might overflow. Because of this, VMs might shut down prematurely.

Known issues in this update

Symptom

After installing this update, you might be unable to change your user account profile picture.

When attempting to change a profile picture by selecting the button Start> Settings > Account > Your info and, under Create your picture, clicking on Browse for one, you might receive an error message with error code 0x80070520.

Workaround

We are working on a resolution and will provide an update in an upcoming release.

KB5039217: Win 10 Ent LTSC 2019 Win 10 IoT Ent LTSC 2019 Windows 10 IoT Core 2019 LTSC Windows Server 2019

Improvements

This security update includes improvements. When you install this KB:

This update affects the version of curl.exe that isin Windows. The version number is now 8.7.1.

This update addresses an issue that affects lsass.exe. It stops responding. This occurs after you install the April 2024 security updates on Windows servers.

This update addresses an issue that affects lsass.exe. It leaks memory. This occurs during a Local Security Authority (Domain Policy) Remote Protocol (LSARPC) call.

KB5039214: Windows 10, version 1607, all editions Windows Server 2016, all editions

This update addresses an issue that affects lsass.exe. It stops responding. This occurs after you install the April 2024 security updates on Windows servers.

This update addresses an issue that affects lsass.exe. It leaks memory. This occurs during a Local Security Authority (Domain Policy) Remote Protocol (LSARPC) call.