|
| 1 | +--- |
| 2 | +title: August 2024 security update (KB 5041573) for Azure Stack HCI, version 23H2 |
| 3 | +description: Read about the August 2024 security update (KB 5041573) for Azure Stack HCI, version 23H2. |
| 4 | +author: alkohli |
| 5 | +ms.topic: conceptual |
| 6 | +ms.date: 08/13/2024 |
| 7 | +ms.author: alkohli |
| 8 | +ms.reviewer: alkohli |
| 9 | +ms.subservice: azure-stack-hci |
| 10 | +--- |
| 11 | + |
| 12 | +# August 2024 OS security update (KB 5041573) for Azure Stack HCI, version 23H2 |
| 13 | + |
| 14 | +[!INCLUDE [applies-to](../../includes/hci-applies-to-23h2.md)] |
| 15 | + |
| 16 | +This article describes the OS security update for Azure Stack HCI, version 23H2 that was released on August 13, 2024 and applies to OS build 25398.1085. |
| 17 | + |
| 18 | +<!--For an overview of Azure Stack HCI, version 23H2 release notes, see the [update history](https://support.microsoft.com/topic/release-notes-for-azure-stack-hci-version-23h2-018b9b10-a75b-4ad7-b9d1-7755f81e5b0b).--> |
| 19 | + |
| 20 | +## Improvements |
| 21 | + |
| 22 | +This security update includes quality improvements. The following key issues and features are present in this update: |
| 23 | + |
| 24 | +- **Stability of clusters on Windows Server 2022**. Servers in the same cluster shutdown when you don't expect them to. This leads to high latency and network availability issues. |
| 25 | + |
| 26 | +- **Bootloader**. A race condition might stop a computer from starting. This occurs when you configure the bootloader to start many operating systems. |
| 27 | + |
| 28 | +- **Autopilot**. Using Autopilot to provision a Surface Laptop SE device fails. |
| 29 | + |
| 30 | +- **Windows Defender Application Control (WDAC)**. A memory leak occurs that might exhaust system memory as time goes by. This issue occurs when you provision a device. |
| 31 | + |
| 32 | +- **Protected Process Light (PPL) protections**. You can bypass them. |
| 33 | + |
| 34 | +- **Windows Kernel Vulnerable Driver Blocklist file (DriverSiPolicy.p7b)**. This update adds to the list of drivers that are at risk for Bring Your Own Vulnerable Driver (BYOVD) attacks. |
| 35 | + |
| 36 | +- **NetJoinLegacyAccountReuse**. This update removes this registry key. For more information, see [KB 5020276 Net join: Domain join hardening changes](https://support.microsoft.com/topic/kb5020276-netjoin-domain-join-hardening-changes-2b65a0f3-1f4c-42ef-ac0f-1caaf421baf8). |
| 37 | + |
| 38 | +- **BitLocker (known issue)**. A [BitLocker recovery screen](/windows/security/operating-system-security/data-protection/bitlocker/recovery-overview) shows when you start up your device. This occurs after you install the July 9, 2024, update. This issue is more likely to occur if [device encryption](https://support.microsoft.com/windows/turn-on-device-encryption-0c453637-bc88-5f74-5105-741561aae838) is on. Go to **Settings > Privacy & Security > Device encryption**. To unlock your drive, Windows might ask you to enter the recovery key from your Microsoft account. |
| 39 | + |
| 40 | +- **Lock screen**. This update addresses CVE-2024-38143. As a result, the **Use my windows user account** check box isn't available on the lock screen to connect to Wi-Fi. |
| 41 | + |
| 42 | +- **Secure Boot Advanced Targeting (SBAT) and Linux Extensible Firmware Interface (EFI)**. This update applies SBAT to systems that run Windows and stops vulnerable Linux EFI (shim bootloaders) from running. This update doesn't apply to systems that dual-boot Windows and Linux. After the update is applied, older Linux ISO images might not boot. If this occurs, work with your Linux vendor to get an updated ISO image. |
| 43 | + |
| 44 | +- **Domain Name System (DNS)**. This update hardens DNS server security to address CVE-2024-37968. If the configurations of your domains aren't up to date, you might get the SERVFAIL error or a time-out. |
| 45 | + |
| 46 | +For more information about security vulnerabilities, see the [Security Update Guide](https://msrc.microsoft.com/update-guide/) and the [August 2024 Security Updates](https://msrc.microsoft.com/update-guide/releaseNote/2024-Aug). |
| 47 | + |
| 48 | +## Known issues |
| 49 | + |
| 50 | +Microsoft isn't currently aware of any issues with this update. |
| 51 | + |
| 52 | +## To install this update |
| 53 | + |
| 54 | +Microsoft now combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see [Servicing stack updates](/windows/deployment/update/servicing-stack-updates) and [Servicing Stack Updates (SSU): Frequently Asked Questions](https://support.microsoft.com/topic/servicing-stack-updates-ssu-frequently-asked-questions-06b62771-1cb0-368c-09cf-87c4efc4f2fe). |
| 55 | + |
| 56 | +To install the LCU on your Azure Stack HCI cluster, see [Update Azure Stack HCI clusters](../update/about-updates-23h2.md). |
| 57 | + |
| 58 | +## File list |
| 59 | + |
| 60 | +For a list of the files that are provided in this update, download the file information for [Cumulative update 5041573](https://go.microsoft.com/fwlink/?linkid=2282056). |
| 61 | + |
| 62 | +## Next steps |
| 63 | + |
| 64 | +- [Install updates via PowerShell](../update/update-via-powershell-23h2.md) for Azure Stack HCI, version 23H2. |
| 65 | +- [Install updates via Azure Update Manager in Azure portal](../update/azure-update-manager-23h2.md) for Azure Stack HCI, version 23H2. |
0 commit comments