Categories: Cyber Security News

Windows 11 Security Update for Versions 22H2 & 23H2 May Cause Recovery Issues

Microsoft’s May 2025 security update for Windows 11 has triggered system instability in certain environments, with users reporting critical boot failures linked to the ACPI.sys driver.

The issue primarily impacts enterprise virtual machines but highlights broader challenges in maintaining compatibility across hybrid infrastructure.

As the company works on a permanent fix, administrators are advised to pause deployments in affected configurations.

The KB5058405 cumulative update, released on May 13, 2025, for Windows 11 versions 22H2 and 23H2, has caused devices to enter recovery mode with the error code 0xc0000098 and a missing/corrupted ACPI.sys file.

This Advanced Configuration and Power Interface driver is fundamental to hardware communication, affecting systems’ ability to initialize components like processors, memory controllers, and power management features.

Microsoft confirmed the problem manifests most frequently in virtualized environments, including Azure Virtual Machines, Azure Virtual Desktop instances, and on-premises deployments using Citrix or Hyper-V platforms.

Physical devices and consumer-grade virtual machines appear largely unaffected, with enterprise IT teams bearing the brunt of disruption.

The company’s engineering team traced the fault to incompatible driver stack interactions in virtualized firmware layers, though a root cause analysis remains ongoing.

Windows 11 Security Update

Organizations relying on cloud-based or hybrid virtual desktop infrastructures face operational hurdles, as affected systems cannot boot into Windows after applying the update.

Early adopters who deployed KB5058405 reported being stuck in a boot loop, with recovery options limited to command-line tools or cloud-based remediation workflows.

The risk profile varies by platform:

  • Azure VMs: Microsoft recommends using the Azure Virtual Machine repair commands toolkit to mount damaged OS disks to healthy VMs for file repairs.
  • Citrix/Hyper-V: Administrators must restore from backups or redeploy master images without the problematic update.
  • Physical devices: Less than 0.3% of non-virtualized systems encountered the bug, primarily those with custom ACPI firmware tables.

Notably, the error occasionally references other system files beyond ACPI.sys, suggesting deeper compatibility issues with the update’s driver validation routines.

Microsoft has temporarily halted automatic deployments to Azure-hosted VMs while urging on-premises administrators to exclude KB5058405 from patch cycles until further notice.

Mitigations

As an interim solution, Microsoft published registry-based workarounds to bypass ACPI.sys checks during boot sequences for advanced users.

However, these tweaks disable critical power management features and are not recommended for production environments.

The Azure support team emphasizes leveraging snapshot-based rollback capabilities in cloud platforms to revert to pre-update states with minimal downtime.

A hotfix is expected by early June 2025, delivered via the Windows Update for Business service and Microsoft Update Catalog.

Enterprise customers can anticipate revised installer packages (KB5058405_rev1) with updated driver compatibility shims. Until then, system administrators should:

  1. Audit virtual machine deployments for pending KB5058405 installations.
  2. Configure update rings to block this specific patch.
  3. Test emergency repair procedures using Azure’s VM repair toolkit.

While consumer editions remain largely unaffected, this incident underscores the growing complexity of maintaining update reliability across diverse hardware and virtualization ecosystems.

Microsoft has committed to enhancing pre-release testing for enterprise configurations, aiming to prevent similar disruptions during future monthly security rollouts.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

The post Windows 11 Security Update for Versions 22H2 & 23H2 May Cause Recovery Issues appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Today’s Top Deals: PS5 Digital Edition Bundle, Pragmata for PC, and Therabody Massage Gun

If you still don’t own a PS5, the Digital Edition Fortnite Flowering Chaos Bundle avoids…

30 minutes ago

Get a Cordless Electric Air Duster For Your PC Maintenance Kit for Just $19.99

Few tools are as useful for simple cleaning and maintenance than a powerful air duster.…

30 minutes ago

Critical Anthropic MCP Vulnerability Enables Remote Code Execution Attacks

A critical vulnerability in Anthropic’s Model Context Protocol (MCP) is putting millions of systems at…

1 hour ago

iTerm2 Flaw Abuses SSH Integration Escape Sequences to Turn Text Into Code Execution

A newly disclosed vulnerability in the popular iTerm2 macOS terminal emulator shows that even viewing…

1 hour ago

Understanding The Rise In ALPRs On Highways

Illustration by Heather Landis An ALPR snaps photos of passing cars. Its purpose is to…

1 hour ago

Get To Know L. Steven Taylor, Actor And Author

Photo by Joan Marcus/Disney Many Broadway actors leave once a contract is up. You’ve been…

1 hour ago

This website uses cookies.