Extended Security Updates
The latest Extended Security Updates coverage — news, analysis, and updates from the WindowsNews.AI desk.
San Diego Lawsuit: Microsoft Accused of Using Windows 10 Sunset to Force AI PC Upgrades
A lawsuit filed in San Diego Superior Court seeks an injunction that would force Microsoft to continue issuing free security updates for Windows 10 indefinitely, upending the company’s long-planned...
Windows 10 Death Clock Ticks to October 14, 2025: The 5 Options You Must Weigh Before It’s Too Late
The atomic clock is ticking, and Microsoft isn’t hitting snooze. Windows 10—still running on nearly 70% of the world’s PCs—will stop receiving security updates on October 14, 2025. For the...
KB5063709 Update Fixes Windows 10 ESU Enrollment Crash, Adds Secure Boot Anti-Rollback
Microsoft has released cumulative update KB5063709 for Windows 10 versions 21H2 and 22H2, pushing system builds to 19044.6216 and 19045.6216, respectively. The August 2025 Patch Tuesday rollout...
KB5063709 Fixes Broken ESU Enrollment on Windows 10, Now at Build 19045.6216
Microsoft’s August 2025 Patch Tuesday delivered KB5063709, a cumulative security update that finally repairs the crashing Extended Security Updates enrollment wizard—a bug that had locked users...
WSL 2.5.10 Fixes TOCTOU Bug: Microsoft Acts Fast on CVE-2025-53788 Privilege Escalation
Microsoft released an out-of-band Windows Subsystem for Linux (WSL) update on August 6, 2025, patching a local elevation-of-privilege vulnerability that could let attackers break out of WSL2...
Critical RRAS Vulnerability Leaks Windows Server Memory—Patch CVE-2025-50157 Immediately
Microsoft has issued an urgent security update for a memory disclosure flaw in Windows Routing and Remote Access Service (RRAS) that could let attackers remotely extract sensitive data from unpatched...
Microsoft Patches Critical Excel Use-After-Free Flaw (CVE-2025-53735) That Executes Code via Malicious Spreadsheets
Microsoft has confirmed a serious use-after-free vulnerability in Microsoft Excel, tracked as CVE-2025-53735, that can allow attackers to execute arbitrary code on a victim’s machine simply by...
Windows 11 KB5063875 August Security Update Combines LCU, SSU, Demands DISM for Uninstall
Microsoft shipped the August 12, 2025 cumulative security update for Windows 11 on schedule, delivering essential protections and quality improvements across supported versions 22H2 and 23H2....
Patch Now: Windows CDPSvc Use-After-Free Bug (CVE-2025-48000) Grants Attackers SYSTEM Privileges
A use-after-free vulnerability in the Windows Connected Devices Platform Service (CDPSvc) lets any local authenticated attacker gain full SYSTEM control—and the fix landed in Microsoft’s July...
Uninitialized Resource Bug in Windows RRAS Could Expose Corporate VPN Secrets, Microsoft Urges Patch
Microsoft has disclosed a new information disclosure vulnerability in the Windows Routing and Remote Access Service (RRAS), tracked as CVE-2025-53719, that could allow an authenticated attacker to...
Microsoft’s August Patch Bundles SSU with Windows 11 23H2/22H2 Security Update and Warns of 2026 Secure Boot Crunch
Microsoft shipped the August 2025 cumulative security update for older Windows 11 branches—KB5063875—on August 12, rolling out a combined latest cumulative update (LCU) and servicing stack update...
KB5064010 Hotpatch: Windows 11 Enterprise LTSC 2024 Now Patched Without Reboots
Microsoft has released KB5064010, a hotpatch for Windows 11 Enterprise LTSC 2024 that delivers critical security fixes without requiring a system restart. The update, issued on August 12, 2025,...