Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Windows Update. Show all posts

Windows 11 KB5101650 and KB5099414 Updates Released With Security Fixes and New Features


 

A cumulative update for Windows 11 based on Patch Tuesday July 2026 is now available, with KB5101650 for versions 25H2 and 24H2 and KB5099414 for version 23H2. As well as addressing 571 security vulnerabilities, the mandatory updates also improve the usability, accessibility, and performance of the operating system. 

Using the Microsoft Update Catalog or by navigating to Settings > Windows Update and selecting Check for updates, users may download the updates manually, following installation. As a result of the installation, Windows 11 build numbers have been updated to 26200.8875 (25H2), 26100.8875 (24H2), and 22631.7376 (23H). It is noteworthy to note the wider rollout of Point-in-Time Restore, which allows users to restore their systems to a previous state in a more efficient manner. 

Aside from new features, Microsoft has introduced several security-focused improvements as part of the July Patch Tuesday release, as well as enhanced controls for enterprise administrators. As a result of improved device targeting in the update, more eligible systems will be able to receive updated Secure Boot certificates automatically via Windows Update, thus expanding Secure Boot certificate deployment. 

Moreover, Microsoft has also upgraded the built-in curl command-line utility to version 8.21.0, which provides additional security features. In addition to reducing unnecessary notifications and taskbar badges, this update also disables automatic opening on hover, and provides more customization options for Widgets. There are several additional improvements to File Explorer, including quicker launch times, improved responsiveness, enhanced support for complex file paths, and new quick actions such as Open File Location and Ask Copilot for work and school accounts. 

Several additional features have been added to enhance accessibility, including a Screen Tint feature which reduces eye strain and improved Magnifier controls that provide the ability to set precise zoom levels for the Magnifier. 

A number of languages are now supported by Voice Access and Voice Typing, including French, German, and Spanish. These languages now support real-time grammar, punctuation, and recognition enhancements, enhancing dictation accuracy. In addition to improving connectivity and hardware reliability, the release also enhances Bluetooth performance by improving device pairing time, microphone synchronization, voice calls that are more reliable, and LE Audio accessory stability.

With networking enhancements, Wi-Fi crashes are reduced, VPN compatibility is improved, virtualization networks are strengthened, and network settings are preserved during operating system upgrades. The security of Remote Desktop (RDP) has also been enhanced by supporting SHA-2 certificate thumbprints for trusted RDP publishers, while maintaining SHA-1 only for backward compatibility. 

In order to reduce phishing risks and prepare for eventually terminating SHA-1 support, organizations are encouraged to migrate to stronger SHA-256 certificates and update Group Policy settings for Remote Desktop files. Furthermore, the cumulative update resolves a compatibility issue that was caused by the June 2026 security update, which prevented third-party applications using OLE Automation from launching Microsoft Office or opening Office files. 

A further step to strengthen network security was taken by Microsoft by implementing stricter registration requirements for Transport Driver Interfaces (TDI). This may affect applications that rely on unregistered third-party TDI transports. Additionally, improved HD Audio reliability, stability of the Start menu, graphics performance on multiple monitors, Windows Subsystem for Linux (WSL) network improvements, improved printer installation that uses the Internet Printing Protocol (IPP) by default, and enhanced touchpad customization options are also included. 

Microsoft has reported no known issues with this month's Patch Tuesday update, which makes it a relatively stable release in comparison with previous Patch Tuesday releases. Considering the large number of security fixes included, users are encouraged to install the updates immediately to ensure protection against recently disclosed vulnerabilities. Also included in this update is a minor modification to the handling of keyboard shortcuts in Windows by altering how hotkey cleanup is conducted. 

There is a possibility that, in rare cases, certain built-in Windows experiences may temporarily cease to respond to specific keyboard shortcuts after installation. Restarting the affected application should typically resolve the issue, and users may also report persistent problems through the Feedback Hub.

Patch Tuesday updates in July 2026 reinforce Microsoft's ongoing commitment to enhancing the security, stability, and user experience of Windows 11. Hundreds of vulnerabilities have been addressed along with new features and reliability enhancements. Users and organizations are encouraged to install the updates as soon as possible to ensure optimal protection.

Microsoft Introduces Enhanced Windows Protected Print Mode for Increased Security

 



Microsoft has revealed the introduction of Windows Protected Print Mode (WPP), a new feature that brings significant security enhancements to the Windows print system. 

According to Johnathan Norman, the principal engineer manager at Microsoft Offensive Research & Security Engineering (MORSE), WPP is built on the existing IPP print stack, supporting only Mopria certified printers and disabling the loading of third-party drivers. Norman emphasized that such measures are crucial for enhancing print security in Windows, addressing vulnerabilities that have historically been exploited, as seen in incidents like Stuxnet and Print Nightmare.

The MORSE team conducted a comprehensive analysis of Windows Print-related cases reported to MSRC, revealing that Windows Protected Print Mode successfully mitigated over half of the vulnerabilities identified. 

Once WPP becomes the default setting on all Windows systems, Microsoft plans to shift away from running the built-in Print Spooler service as SYSTEM. Instead, it will be launched as a restricted service, significantly reducing its access to resources and privileges. This strategic move aims to diminish the appeal of the Spooler process as a potential target for exploitation.

In addition to changing the Spooler service configuration, Microsoft will eliminate various attack vectors previously exploited by malicious actors. This includes the removal of RPC endpoints and legacy components that have been targeted in the past. WPP will also introduce binary mitigations, such as Control Flow Enforcement Technology (CFG), Child Process Creation Disabled, Redirection Guard, and Arbitrary Code Guard, making exploitation more challenging.

When WPP mode is enabled, normal spooler operations will go through a new Spooler that incorporates multiple security improvements. These include Limited/Secure Print Configuration, Module Blocking, Per-User XPS Rendering, and Better Transport Security. The goal is to provide users with the most secure default configuration while allowing flexibility to revert to legacy (driver-based) printing if compatibility issues arise.

Microsoft assures users that the implementation of WPP will not impact customers with older printers, as they can enable legacy support. Additionally, as part of a broader printer driver strategy, Microsoft announced the gradual discontinuation of third-party printer driver delivery through Windows Update. 

Starting in 2025, driver submissions from printer vendors will be blocked, with a transition to prioritizing in-house Windows IPP Class drivers by 2026. By 2027, Microsoft plans to cease distributing third-party printer driver updates via Windows Update, except for security fixes, while users can still install drivers from vendors' websites. Norman emphasized that this move away from driver-based printing enables Microsoft to make meaningful improvements to the print system, addressing modern threats more effectively.