in ,

The latest cumulative update may cause Windows Server 2008~2022 to restart. It is recommended to temporarily delete the update.


Microsoft released regular monthly updates to supported versions of Windows 10/11 on April 9, which also includes update KB5036909 for Windows Server 2022.

At present, this update has been found to have serious problems. This problem may even cause Windows Server 2022 to automatically restart, which may cause interruption to corporate business during the restart.

Specifically, after installing update KB5036909, if IT administrators are using the NTLM authentication protocol on Windows Server 2022, they may notice a sudden surge in NTLM protocol traffic, causing the Local Security Authority Subsystem Service (i.e. LSASS.exe) to crash. , a crash may cause Windows Server to be forced to restart the system without warning.

The latest cumulative update may cause Windows Server 2008~2022 to restart. It is recommended to temporarily delete the update.

In fact, this problem does not only affect Windows Server 2022. It is currently known that all Windows Server versions have the same problem after installing the April update.

Affected include:

  • Windows Server 2022 – KB5036909
  • Windows Server 2019 – KB5036896
  • Windows Server 2016 – KB5036899
  • Windows Server 2012 R2 – KB5036960
  • Windows Server 2012 – KB5036969
  • Windows Server 2008 R2 – KB5036967
  • Windows Server 2008 – KB5036932

There is currently no solution to mitigate this problem. If an enterprise uses the server where Windows Server is installed as a domain controller (DC) and uses the NTML authentication protocol, it may encounter this problem. When Windows Server restarts, it will no longer be able to provide NTML authentication services. The verification service cannot be restored until the restart of each service is completed.

For servers that do not serve as DCs and enterprises that do not use NTLM, there is no need to deal with this problem. If you use the above services, what you can currently consider is to temporarily delete the update. Of course, this will weaken security. The 2024-04 monthly update has fixed some security vulnerabilities. , but before Microsoft releases an update to fix it, the use of Windows Server DC can only be restored by deleting the update.

Copyright Statement: Thank you for reading. Unless the source website name or link is indicated in the article, it is the original content of Blue Dot.com.When reprinting, please be sure to indicate: Source: bluedot.com, author andFull link to this article,Thank you for understanding.

What do you think?

Leave a Reply

Your email address will not be published. Required fields are marked *

GIPHY App Key not set. Please check settings

Development trends and application scenarios of generative artificial intelligence

El Salvador suffered a massive leak of biometric data