Microsoft has released an emergency out-of-band (OOB) update for Windows Server 2019 that fixes numerous critical bugs introduced during the January 2022 Patch Tuesday.
Soon after Windows Server admins installed the January 2022 updates, they began reporting severe issues, including domain controllers entering into boot loops, Hyper-V no longer starting, L2TP VPN connections failing, and ReFS volumes becoming inaccessible.
The issues were severe enough that many admins chose to uninstall the updates and forgo the included security fixes so that their servers could operate correctly again.
OOB updates for all Server versions released
Yesterday, Microsoft released OOB updates for Windows Server 2022, Windows Server 20H2, Windows Server 20H1, Windows Server 2016, and Windows Server 2012 R2 to fix all of these issues.
Microsoft also released security updates for Windows 10, Windows 8, and Windows 7 operating systems to resolve the LT2P connection issues.
However, the KB5010791 OOB update for Windows 2019 was not ready yesterday and was finally released this evening with the following fixes:
-
Addresses a known issue that might cause IP Security (IPSEC) connections that contain a Vendor ID to fail. VPN connections using Layer 2 Tunneling Protocol (L2TP) or IP security Internet Key Exchange (IPSEC IKE) might also be affected.
-
Addresses a known issue that might cause Windows Servers to restart unexpectedly after installing the January 11, 2022 update on domain controllers (DCs).
-
Addresses an issue that prevents Active Directory (AD) attributes from being written properly during a Lightweight Directory Access Protocol (LDAP) modify operation when you make multiple attribute changes.
-
Addresses an issue that might prevent removable media that is formatted using the Resilient File System (ReFS) from mounting or might cause the removable media to mount in the RAW file format. This issue occurs after installing the January 11, 2022 Windows update.
Microsoft states that the Windows Server 2019 KB5010791 update is available for Windows Update and the Microsoft Catalog. However, it is not currently available in WSUS and must be imported manually.
The complete list of the OOB updates released to fix the January 2022 bugs are listed below.
The following updates can only be downloaded and installed via the Microsoft Update Catalog:
Updates for the following Windows versions are also available through Windows Update as an optional update:
- Windows 11, version 21H1 (original release): KB5010795
- Windows Server 2022: KB5010796
- Windows 10, version 21H2: KB5010793
- Windows 10, version 21H1: KB5010793
- Windows 10, version 20H2, Windows Server, version 20H2: KB5010793
- Windows 10, version 20H1, Windows Server, version 20H1: KB5010793
- Windows 10, version 1909, Windows Server, version 1909: KB5010792
- Windows Server 2019: KB5010791
- Windows 10, version 1607, Windows Server 2016: KB5010790
- Windows 10, version 1507: KB5010789
- Windows 7 SP1: KB5010798
- Windows Server 2008 SP2: KB5010799
Windows Server admins who installed yesterday's OOB updates report that they fixed the issues with the January updates.
Comments
markddimalanta - 2 years ago
Hi,
For 2012 R2, Do we need to install the January 2022 patch (KB5009624) that has an issue then install the Out-of-band updates (KB5010794) ?
Or just install the Out-of-band updates (KB5010794) and ignore the previous release patch?
NoneRain - 2 years ago
Based on its size, you probably should install the Jan Patch and the fix.
Usually oob says when it replaces an update.
JustinFlynn - 2 years ago
I think this says that the fix is rolled into these re-releases. https://www.bleepingcomputer.com/news/microsoft/microsoft-resumes-rollout-of-january-windows-server-updates/
I plan to download the "Fixes" just to have on hand in case I need to use them. I'll still give it a couple of days before I patch.
noelprg4 - 2 years ago
some of these out-of-band updates for Win11 and recent Win10 versions have been superseded by newly released 1/25 preview updates:
KB5009608 for Windows Server 2022 - build 20348.502
KB5008353 for Windows 11, version 21H2 - build 22000.469
KB5009596 for Windows 10 versions 20H2, 21H1 & 21H2 - build 1904x.1503
KB5009616 for Windows Server 2019, Windows 10 Enterprise LTSC 2019 - build 17763.2510
NJJoe - 2 years ago
Question: What exactly is the proper procedure, install the bad KB's & the optional OOB update at the same time? What success have you guys had? Thanks in advance.