KB5055523Catastrophic

BSOD, inetpub chaos, Windows Hello broken

BSODBootWindows HelloIISSecurity

What broke

April’s update was a masterclass in unintended consequences. Systems with Secure Launch enabled hit SECURE_KERNEL_ERROR BSODs (0x18B), requiring emergency OOB patches within three days. The update created a mysterious C:\inetpub folder on every PC — even without IIS installed — to fix a symlink vulnerability. Security researchers promptly discovered this fix introduced a new vulnerability: non-admin users could use the folder to block all future Windows updates via a symlink attack. Windows Hello facial recognition broke for anyone using a privacy shutter on their color camera while relying on the IR sensor. And WSUS couldn’t upgrade systems to 24H2 anymore. One update, four distinct disasters.

Sources

  1. Windows Latest: KB5055523 incident report
  2. Born's Tech and Windows World: KB5055523 incident report
  3. doublepulsar.com: KB5055523 incident report

Related Windows update incidents