CVE‑2026‑25177

Ardiansyah Permana 60 Reputation points
2026-04-17T08:00:44.3666667+00:00

Hello Tim,

Can CVE‑2026‑25177 be covered by the Patch Tuesday update KB5082123?

Windows for business | Windows Server | Devices and deployment | Install Windows updates, features, or roles

Locked Question. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Harry Phan 33,480 Reputation points Independent Advisor
2026-04-17T08:30:26.7733333+00:00

Hi Ardiansyah,

No, CVE‑2026‑25177 is not covered by KB5082123. That vulnerability in Active Directory Domain Services was addressed in the March 2026 Patch Tuesday release, not in the April update KB5082123, which focuses on Secure Boot certificate expiration and related system integrity fixes.

CVE‑2026‑25177 is an elevation‑of‑privilege flaw in AD DS caused by improper restriction of file and resource names. Microsoft rated it as high severity (CVSS 8.8) and released a dedicated fix in March 2026. If your environment relies on Active Directory, you need to ensure that the March 2026 cumulative update containing that patch is installed across all domain controllers. KB5082123, released in April 2026, does not remediate this CVE; it instead prepares systems for upcoming Secure Boot certificate expirations in June 2026. Applying KB5082123 alone will leave your AD DS infrastructure exposed to CVE‑2026‑25177.

To confirm coverage, check the Microsoft Security Update Guide for March 2026 and verify that the patch for CVE‑2026‑25177 is applied. If your servers are only on KB5082123, you must backfill the March update or a later cumulative update that explicitly lists CVE‑2026‑25177 as resolved. This ensures your domain controllers are protected against privilege escalation attempts.

I hope this information clarifies your question. If it does, please mark the answer as accepted or give it a thumbs up to let me know. Wishing you a great day ahead.

Harry.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful