Microsoft Windows 11 Update KB5074109 Fixes 100+ Flaws

Microsoft Windows 11 Update KB5074109 Fixes 100+ Flaws

Microsoft’s January 2026 Patch Tuesday (KB5074109) delivers fixes for 114 vulnerabilities across its product ecosystem, including an actively exploited zero-day in Windows Desktop Window Manager (DWM).

The update applies to Windows 11 versions 24H2 and 25H2, introducing critical security patches, hardening measures, and updates to AI components.

Key Zero-Day Vulnerability

The most significant fix addresses CVE-2026-20805, a locally exploitable information disclosure flaw in DWM. Microsoft confirmed this vulnerability has been actively exploited. Attackers with local access and low privileges could extract sensitive memory data by abusing DWM’s interaction with Advanced Local Procedure Call (ALPC) ports. The issue was discovered by Microsoft’s Threat Intelligence Center and Security Response Center, though technical details remain limited.

Other High-Risk Vulnerabilities

Several additional vulnerabilities are marked as “exploitation more likely,” signaling elevated risk:

  • CVE-2026-20816 – Privilege escalation in Windows Installer
  • CVE-2026-20817 – Elevation of privilege via Windows Error Reporting
  • CVE-2026-20840 – NTFS vulnerability
  • CVE-2026-20843 – Routing and Remote Access Service (RRAS) flaw
  • CVE-2026-20860 – Ancillary Function Driver for WinSock vulnerability
  • CVE-2026-20871 – Additional DWM vulnerability (distinct from the zero-day)

These components are deeply integrated into Windows 11, making them attractive targets for privilege escalation and lateral movement within enterprise environments.

Deprecation of Legacy Components

The update also removes support for outdated modem drivers, including agrsm64.sys and smserial.sys, reducing the attack surface by retiring unmaintained, low-use hardware dependencies.

Microsoft resolved RemoteApp connection failures in Azure Virtual Desktop, a problem introduced by previous updates. Additionally, a networking bug in Windows Subsystem for Linux (WSL) that disrupted corporate VPN access under mirrored networking configurations has been fixed.

Power efficiency improvements were included as well. Devices equipped with Neural Processing Units (NPUs) will now correctly enter idle states. Previously, NPUs remained powered while idle, causing unnecessary battery drain.

Windows 11 users can install the latest security update through Settings > Windows Update > Check for updates > Install all

Related Posts