November 8, 2022 - KB5020010 (security update only) (2023)

release date:

August 11, 2022


security updates only


Learn more about this security-only update, including improvements, any known issues, and how to get the update.

remindWindows 8.1Support will end on January 10, 2023, at which time technical assistance and software updates will no longer be provided. If you have devices running Windows 8.1, we recommend updating them to a newer, available, and supported version of Windows. If your device doesn't meet the technical requirements to run a newer version of Windows, we recommend that you replace your device with a Windows 11-compatible device.

Microsoft will not provide an Extended Security Update (ESU) program for Windows 8.1. Continuing to use Windows 8.1 after January 10, 2023 may increase an organization's security risks or impact its ability to meet its compliance obligations.

For more information, seeWindows 8.1 support ends on January 10, 2023.

Windows Server 2012 R2Support for Datacenter, Essentials, Embedded Systems, Foundation, and Standard will end on October 10, 2023.

observeFor information on the various types of Windows updates such as critical, security, drivers, service packs, etc., see the followingarticleFor additional notes and news, see Windows 8.1 and Windows Server 2012 R2 Update Historyhome page.


This security-only update includes important changes to:

  • Updates Jordan for Daylight Saving Time (DST) to prevent clocks from going back 1 hour on October 28, 2022. Also changed the display name for Jordan Standard Time from "(UTC+02:00) Amman" to "(UTC +03: 00) Amman".

  • Addresses an issue where the forest trust creation process fails to populate the DNS name suffix in the trust information properties after installing an update on or after January 11, 2022.

  • Addressed security vulnerabilities in the Kerberos and Netlogon protocols, as described inCVE-2022-38023,CVE-2022-37966, electronicCVE-2022-37967.For deployment guidance, see the following articles:

    • KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967

    • KB5021130: How to manage Netlogon protocol changes related to CVE-2022-38023

    • KB5021131: How to manage Kerberos protocol changes related to CVE-2022-37966

    For more information on addressed security vulnerabilities, seeDeployment | Security Update Guideit is atNovember 2022 Security Updates.

For more information on addressed security vulnerabilities, seeDeployment | Security Update Guideit is atNovember 2022 Security Updates.

Known issues in this update


Next step

After installing this update or a later version of Windows Update, domain join operations might fail with error "0xaac (2732): NERR_AccountReuseBlockedByPolicy". Additionally, the text "An account with the same name exists in Active Directory. Account reuse is blocked by security policy" may appear.

Affected scenarios include certain domain join or reimaging operations where the computer account is created or provisioned by an identity other than the identity used to join or rejoin the computer to the domain.

For more information on this issue, seeKB5020276—Netjoin: Domain join implementation changes.

observeConsumer desktop versions of Windows are less likely to have this issue.

This issue has been resolvedKB5023764.

After installing Windows Updates released on or after November 8, 2022 on a Windows server using the Domain Controller role, you may experience Kerberos authentication issues. This issue may affect any Kerberos authentication in your environment. Some scenarios that may be affected:

  • Domain user login may fail. This also affectsActive Directory Federation Services (AD FS)verify.

  • Group Managed Service Account (gMSA)for services such asInternet Information Services (IIS Web Server)Authentication may fail.

  • Remote Desktop Connection using a domain user may fail to connect.

  • You may lose access to shared folders on workstations and file shares on servers.

  • Printing that requires domain user authentication may fail.

When you encounter this issue, you may receive a Microsoft-Windows-Kerberos-Key-Distribution-Center ID 4 error event with the following text in the System section of the domain controller event log.

observeAffected events will contain "The missing key has ID 1"Korda:

When processing an AS request to the target service, billThere is no correct key to generate the Kerberos ticket (the missing key has ID 1). Requested etypes: 18 3. Available account etypes: 23 18 17. Change or reset account passwordA suitable key will be generated.

observeThis question is not part of the expectedSecurity hardening for Netlogon and Kerberos as of November 2022 Security Update.Even if the problem is resolved, you must still follow the instructions in these articles.

Windows devices that consumers use at home or that are not part of the local domain are not affected by this issue. Non-hybrid Azure Active Directory environments without an on-premises Active Directory server are not affected.

This issue has been resolved in an update.KB5021653.

After you install this update or a later update on a domain controller (DC), you may experience a memory leak in the Local Security Authority Subsystem Service (LSASS.exe). Depending on your domain controller workload and the amount of time since the last server restart, LSASS may continue to increase memory usage as the server functions normally, and the server may stop responding or restart automatically.

observeOut-of-band updates for DCs released on November 17, 2022 and November 18, 2022 may be affected by this issue.

To alleviate this issue, open a command prompt as administrator and set the registry key withKrbtgtFullPacAssinaturafor0:

reg 添加 "HKLM\System\CurrentControlSet\services\KDC" -v "KrbtgtFullPacSignature" -d 0 -t REG_DWORD

observeAfter fixing this known issue, you should setKrbtgtFullPacAssinaturato a higher setting, depending on what your environment allows. We recommend that you enable enforcing mode as soon as your environment is ready.

For more information on this registry key , seeKB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967.

We are working on a resolution and will provide an update in a future release.

Applications that use ODBC connections to access databases through the Microsoft ODBC SQL Server Driver (sqlsrv32.dll) may fail to connect after you install this update. Additionally, you may receive application errors or you may receive SQL Server errors. Errors you may receive include the following messages:

  • The EMS system has encountered a problem.
    Message: [Microsoft][ODBC SQL Server Driver]Protocol error in TDS stream.

  • The EMS system has encountered a problem.
    Message: [Microsoft][ODBC SQL Server Driver] An unknown token was received from SQL Server.

Note for developers:Applications affected by this issue may not be able to obtain data, for example when usingSQLFetch function.This problem may occur when callingSQLBindCol functionbefore calling SQLFetch orSQLGetData functionAfter SQLFetch, when a value of 0 (zero) is supplied for the "BufferLength" parameter of a fixed data type larger than 4 bytes (such as SQL_C_FLOAT).

To determine if you are using an affected application, open the application that is connected to the database. Open a Command Prompt window, type the following command and press Enter:

task list /m sqlsrv32.dll

If the command returns a task, the application may be affected.

To alleviate this problem, you can do one of the following:

  • If your application is already using or can useData Source Name (DSN)Select ODBC connection, installMicrosoft ODBC Driver 17 for SQL Serverand select it for applications that use the DSN.

    observe:We recommend the latest version ofMicrosoft ODBC Driver 17 for SQL Server, because it is more compatible with applications currently using the legacy Microsoft ODBC SQL Server Driver (sqlsrv32.dll) than the Microsoft ODBC Driver 18 for SQL Server.

  • If your application cannot use DSNs, it needs to be modified to allow DSNs or use an ODBC driver newer than the Microsoft ODBC SQL Server Driver (sqlsrv32.dll).

This question is already inKB5022346.If you have implemented the above workaround, it is recommended that you continue to use the configuration in the workaround.

How to get this update

before installing this update

We strongly recommend that you install the latest Servicing Stack Update (SSU) for your operating system before installing the latest Rollup. SSU improves the reliability of the update process to mitigate potential issues when installing Rollups and applying Microsoft security patches. For general information on SSU, seeServicing stack updateelectronicServicing Stack Updates (SSU): Frequently Asked Questions.

If you use Windows Update, the latest SSU (KB5018922) will be provided to you automatically. To get a standalone package of the latest SSU, go toMicrosoft Update Catalog.

remindIf you are using security-only updates, you will also need to install all previous security-only updates and the latest cumulative update for Internet Explorer (KB5019958).

language pack

If you install a language pack after installing this update, you must reinstall it. Therefore, we recommend that you install all required language packs before installing this update. For more information, seeAdd language packs to Windows.

install this update

release channel


Next step

Windows Update and Microsoft Update


See other options below.

Microsoft Update Catalog


To get the standalone package for this update, go toMicrosoft Update Catalogwebsite on the internet.

Windows Server Update Services (WSUS)


If you configure this update will automatically sync with WSUSProducts and Ratingsas follows:

product: Windows 8.1, Windows Server 2012 R2, Windows Embedded 8.1 Industry Enterprise, Windows Embedded 8.1 Industry Pro

Classification: security updates

file information

For a list of the files provided in this update, please downloadUpdate file information for KB5020010.


learnstandard termsUsed to describe Microsoft software updates.


What happens after installing updates released on November 8 2022? ›

After installing updates released on November 8, 2022 or later on Windows Servers with the Domain Controller role, you might have issues with Kerberos authentication. This issue might affect any Kerberos authentication in your environment. Some scenarios that might be affected: Domain user sign in might fail.

What is the Windows Update for November 8 2022? ›

The November 8, 2022 security update (KB5019962) for Azure Stack HCI is delivered from the release channels below. To install it on your Azure Stack HCI cluster, see Update Azure Stack HCI clusters. None. This update will be downloaded and installed automatically from Windows Update.

What is the Microsoft security update summary for November 2022? ›

Microsoft has fixed 65 new vulnerabilities (aka flaws) in the November 2022 update, including ten (10) vulnerabilities classified as critical as they allow Denial of Service (DoS), Elevation of Privilege (EoP), and Remote Code Execution (RCE).

Do I need to install all cumulative updates Windows 10? ›

If you don't install the latest servicing stack update, there's a risk that your device can't be updated with the latest Microsoft security fixes. Microsoft publishes all cumulative updates and SSUs for Windows 10, version 2004 and later together as one cumulative monthly update to the normal release category in WSUS.

What are the problems with Windows 10 update November 2022? ›

After installing updates released November 2022, you might have Kerberos authentication issues. You might experience an error in which the desktop or taskbar disappearing then reappearing. You might be unable to signout or unlink your OneDrive account and sites or folders from Microsoft Teams and SharePoint.

What is the latest Android update 2022? ›

Android 13 is the 13th major release of Google's Android operating system, released for the public on August 15, 2022. Codenamed Tiramisu, it was announced in an Android blog back in February, followed by Beta 1, Beta 2 and Beta 3 in April, May and June respectively.

Should i upgrade to Windows 11 in November 2022? ›

The most recent Windows 11 2022 Update sets the pace for how these annual updates will look. It's feature-packed, especially compared to the slow pace of updates in the Windows 10 era. This update features everything from small user interface tweaks to the Start menu to entirely new apps like Clipchamp.

What is the new Windows latest update? ›

When the Windows 10 2022 Update aka Windows 10, version 22H2 is ready for your device, it will be available to download from the Windows Update page in Settings. Choose a time that works best for you to download the update. You'll then need to restart your device and complete the installation.

What is the latest Windows Update for? ›

As of May 2023, the latest major update to Windows 11 is Windows 11 Version 22H2, referred to as the Windows 11 2022 Update. Updating is automatic through Windows Update.

Are Microsoft security only updates cumulative? ›

Updates for the Windows client OS are typically cumulative. They include all previously released fixes to guard against fragmentation of the operating system. Reliability and vulnerability issues can occur when only a subset of fixes is installed.

Why do you have to wait a month for Microsoft security Info to change? ›

When all security info is removed from a Microsoft account, the account is put into a restricted state for 30-days. While we understand this 30-day period might be frustrating, this is done to protect and alert you in case the security info was removed by someone who had unauthorized access to your account.

What is the new update for Office 2022? ›

In Microsoft Office 2022, adds up to 100 GB of free storage for cloud users, which promotes the speed of operating and work efficiency. 2. The latest Microsoft Office 2022 that Microsoft cracked here comes with a host of updates to Microsoft Word, Spreadsheet, Powerpoint, and all other tools. 3.

What is the latest KB update for Windows 10? ›

Windows 10 version 21H2 is the most current release today. This feature update is known as the “November 2021 Update,” it's been available since November 16, 2021, and the latest quality update is “build 19045.2965.” You can use these instructions to check the version installed on your device.

What is the difference between cumulative update and security only update? ›

Security-only updates are product specific that includes all the security updates whereas, Monthly Rollups are cumulative set of updates which addresses both security and non-security issues.

What happens if you don't update your PC? ›

Security. Updates often patch newly discovered security vulnerabilities, fixing loopholes that could otherwise be used to attack your system. Therefore, if you're running older versions of your operating system and other programs, you leave your computer open to these exploits.

Should I update Windows 10 November update? ›

The best answer is “yes,” when Microsoft released Windows 10 21H2 on November 16, the update was signed off as stable and safe to install on devices running versions 2004, 20H2, and 21H1.

What is the Windows 10 21H2 November 2022 update? ›

Summary. On November 30, 2022, an out-of-band update was released to improve the Windows 10, version 2004, 20H2, 21H1, 21H2, and 22H2 out-of-box experience (OOBE). It provides eligible devices with the option to upgrade to Windows 11 as part of the OOBE process.

What are the problems with the latest Windows 10 update 2023? ›

This update seems to be causing a raft of issues for users, including Blue Screen of Death errors. One of the most serious reported problems involves an error message “PROCESS1 INITIALIZATION FAILED”.

What is the latest Samsung update called? ›

One UI 5 is the latest update for Samsung Galaxy phones and tablets.

What is the most current Android update? ›

Android 12 is the twelfth major release and 19th version of Android, the mobile operating system developed by the Open Handset Alliance led by Google. The first beta was released on May 18, 2021.

What is the latest Android version nov 2022? ›

1.0November 7, 2022Bulletin Published
1.1November 9, 2022Bulletin revised to include AOSP links
2.0December 7, 2022Revised CVE table
Nov 1, 2022

What is the downside to upgrading to Windows 11? ›

Although Windows 11's taskbar looks impressive, it can be considered a downgrade for various reasons. Users may not be able to shift the taskbar to any part of the screen like Windows 10. Instead, it's fixed at the bottom of the screen. One of the most critical drawbacks of Windows 11 is that you can't run it.

Is Windows 11 good now 2023? ›

Overall, I would recommend Windows 11 as a solid and modern operating system that offers many useful features and a great user experience. Pros: I really liked the new interface of Windows 11. The Start menu and taskbar were redesigned, and the overall look and feel of the operating system felt modern and polished.

When can you not upgrade to Windows 11? ›

If your existing Windows 10 PC is running the current version of Windows 10 and meets the minimum hardware specifications to run Windows 11, it will be able to upgrade.

How do I manually update Windows? ›

To manually check for the latest recommended updates, select Start > Settings > Update & Security > Windows Update , and then select Check for updates.

Is Windows 11 still free? ›

Can I upgrade for free? Upgrades to Windows 11 from Windows 10 will be free. Due to the size of the download, however, ISP fees may apply for downloads that occur over metered connections.

How do I manually update Windows 10? ›

How to Update Windows 10 Manually
  1. Open the Windows Start Menu. ...
  2. Then click Settings. ...
  3. Next, click Update & Security.
  4. Then select Install Now or Check for Updates. ...
  5. Next, wait for the update to be installed. ...
  6. Finally, click Restart now after the update is installed.
Jan 25, 2023

What is the KB number for Windows 10 21H2? ›

KB5003791: Update to Windows 10, version 21H2 by using an enablement package.

What is the feature update to Windows 10 version 21H2? ›

The feature update to Windows 10 version 21h2 has inspired the business and IT communities. And some of its features are: Strengthen WIFI security with the standard support of WPA3 H2E. New add Graphics processing unit(GPU) computer is completely supported by the Windows Subsystem for Linux.

How to update from 21H2 to 22H2? ›

To upgrade to Windows 11 22H2 from Windows 11 21H2 or Windows 10 with an ISO file, use these steps:
  1. Open Microsoft Support website.
  2. Under the “Download Windows 11 Disk Image (ISO)” section, select the Windows 11 option.
  3. Click the Download button.
  4. Select the installation language.
  5. Click the Confirm button.
May 8, 2023

What does KB mean in Microsoft updates? ›

Knowledge Base (KB) – Microsoft KBs are a repository of articles describing issues affecting Windows and other Microsoft products. Security updates start with the letters KB and refer to a specific Knowledge Base article; each KB contains a number of updates and patches.

What is security only update? ›

Security-only update

An update that collects all the new security updates for a given month and for a given product, addressing security-related vulnerabilities. It's distributed through Windows Server Update Services (WSUS), System Center Configuration Manager and Microsoft Update Catalog.

How long does it take for Microsoft to update security info? ›

Updating your security proofs takes 30 days. Note We can't expedite this process. During the 30-day period, you can sign in on your device, but there will be certain things you can't do with your account.

Does Microsoft lock your computer for security reasons? ›

Microsoft would never block your computer. If this is a pop-up scam – close the window or restart the browser. If this doesn't help, look for suspicious extensions and apps in your browser and computer. You should also get a reliable antivirus such as TotalAV to scan your computer for malware.

How to bypass Microsoft security? ›

Select Start and type "Windows Security" to search for that app. Select the Windows Security app from the search results, go to Virus & threat protection, and under Virus & threat protection settings select Manage settings. Switch Real-time protection to Off. Note that scheduled scans will continue to run.

Do you have to keep renewing Microsoft Office? ›

Yes, Office 365 does expire if you don't renew your subscription. If you don't renew your subscription, you will lose access to all the Office apps and services that are included in your subscription. This includes Word, Excel, PowerPoint, Outlook, and more.

Will Office 2010 still work after 2022? ›

On 1 May 2022, Office 2010 will no longer be supported and will be switched off by Microsoft.

How do I get the latest Office update? ›

Newer versions of Office

Go to File > Account (or Office Account if you opened Outlook). Under Product Information, choose Update Options > Update Now. Note: You may need to click Enable Updates first if you don't see the Update Now option right away. Close the "You're up to date!"

What are the Microsoft security updates for October 2022? ›

Microsoft Office Security Update for October 2022

Microsoft has released October 2022 security updates to fix multiple security vulnerabilities. Successful exploitation allows an attacker to execute code remotely. Refer to Microsoft Security Guidance for more details pertaining to this vulnerability.

What is the KB for 21H1 feature update? ›

KB5000736: Featured update to Windows 10, version 21H1 by using an enablement package.

How to install KB update Windows 10? ›

Windows 10 and Windows 11
  1. Click the Start button (Windows icon) and choose Settings.
  2. Click Update & security (Windows 10) or Windows Update (Windows 11)
  3. Click Check for updates and install the listed updates.

How do I manually install a Windows KB update? ›

Select Start > Control Panel > Security > Security Center > Windows Update in Windows Security Center. Select View Available Updates in the Windows Update window. The system will automatically check if there's any update that need to be installed, and display the updates that can be installed onto your computer.

Do I need to install all cumulative updates? ›

Yes , you need to install the cummulative updates available in your device to keep your device up to date, those updates are needed to improve your security and performance of your computer.

Is it necessary to install cumulative update? ›

Cumulative updates for Windows 11 are not necessary, but they can help improve the stability and security of your computer. If you are having problems with your computer, you may want to consider installing a cumulative update.

Should I install optional cumulative update? ›

To make your device work well, you should not install optional driver updates because some of the updates are not the new ones. These updates may cause new issues in your system. Fortunately, these updates are optional. You can deselect them to not install them.

What happens after software update? ›

Software Updates Offer New Features

For example, upgraded system enhancements can change your phone's user interface or add extra features such as health features that can track your steps, accurate weather updates and improvements in voice recognition.

What happens after update? ›

The updated version usually carries new features and aim at fixing issues related to security and bugs prevalent in the previous versions. The updates are usually provided by a process referred to as OTA (over the air). You will receive a notification when an update is available on your phone.

What does 2022 update do? ›

The 2022 Update adds support for a new feature called Voice Access, which makes it possible to navigate the entire Windows interface using voice commands. You can select and edit text, control the mouse and keyboard, interact with apps, and switch between command and voice modes.

What happens after iOS 15 update? ›

iOS 15 brings audio and video enhancements to FaceTime, including spatial audio and Portrait mode.


Top Articles
Latest Posts
Article information

Author: Allyn Kozey

Last Updated: 09/13/2023

Views: 6055

Rating: 4.2 / 5 (43 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Allyn Kozey

Birthday: 1993-12-21

Address: Suite 454 40343 Larson Union, Port Melia, TX 16164

Phone: +2456904400762

Job: Investor Administrator

Hobby: Sketching, Puzzles, Pet, Mountaineering, Skydiving, Dowsing, Sports

Introduction: My name is Allyn Kozey, I am a outstanding, colorful, adventurous, encouraging, zealous, tender, helpful person who loves writing and wants to share my knowledge and understanding with you.