Hi Ardiansyah,
No, CVE‑2026‑25177 is not covered by KB5082123. That vulnerability in Active Directory Domain Services was addressed in the March 2026 Patch Tuesday release, not in the April update KB5082123, which focuses on Secure Boot certificate expiration and related system integrity fixes.
CVE‑2026‑25177 is an elevation‑of‑privilege flaw in AD DS caused by improper restriction of file and resource names. Microsoft rated it as high severity (CVSS 8.8) and released a dedicated fix in March 2026. If your environment relies on Active Directory, you need to ensure that the March 2026 cumulative update containing that patch is installed across all domain controllers. KB5082123, released in April 2026, does not remediate this CVE; it instead prepares systems for upcoming Secure Boot certificate expirations in June 2026. Applying KB5082123 alone will leave your AD DS infrastructure exposed to CVE‑2026‑25177.
To confirm coverage, check the Microsoft Security Update Guide for March 2026 and verify that the patch for CVE‑2026‑25177 is applied. If your servers are only on KB5082123, you must backfill the March update or a later cumulative update that explicitly lists CVE‑2026‑25177 as resolved. This ensures your domain controllers are protected against privilege escalation attempts.
I hope this information clarifies your question. If it does, please mark the answer as accepted or give it a thumbs up to let me know. Wishing you a great day ahead.
Harry.