April Patch Tuesday arrives for Windows 10 20H2 and 2004 fixing bugs and erasing Edge Legacy forever
Table of contents:
We are on Tuesday and following the monthly custom, Microsoft has released a new Patch Tuesday. Every second Tuesday of the month we have a new build to bring to teams and this time it comes in the form of Builds 19041.928 and 19042.928 for Windows 10 2004 and 20H2
Two compilations that come with the KB5001330 patch and offer some interesting things. And it is that together with the elimination and correction of errors, both updates completely and definitively eliminate any trace of the classic Edge, which now sees the Chromium-powered version of Edge take its place.
Improvements and fixes
-
"
- Microsoft removed the unsupported legacy Microsoft Edge desktop app in March 2021. In this April 13, 2021 release, we&39;ll be installing the new Microsoft Edge. For more information, see New Microsoft Edge to replace Microsoft Edge Legacy>."
- Updates to improve security when Windows performs basic operations.
- Updated to improve security when using input devices such as a mouse, keyboard, or pen.
- "Fixes an issue where a trusted MIT domain principal fails to obtain a Kerberos service ticket from Active Directory domain controllers (DCs).This occurs on devices that have installed Windows updates that contain the CVE-2020-17049 guardrails and set PerfromTicketSignature to 1 or later. These updates were released between November 10, 2020 and December 8, 2020. Ticket acquisition also fails, KRB_GENERIC_ERROR, if callers send a Ticket Granting Ticket (TGT) without PAC as ticket of evidence without providing the USER_NO_AUTH_DATA_REQUIRED flag input."
- Fixes a issue with security vulnerabilities identified by a security researcher. Due to these security vulnerabilities, this and all future Windows updates will no longer contain the RemoteFX vGPU feature. For more information about the vulnerability and its removal, see CVE-2020-1036 and KB4570006. Secure vGPU alternatives are available with Discrete Device Assignment (DDA) on LTSC versions of Windows Server (Windows Server 2016 and Windows Server 2019) and sac versions of Windows Server (Windows Server, version 1803 and later).
- Addresses a potential elevation of privilege vulnerability in the way that Azure Active Directory web login allows arbitrary browsing from third-party endpoints used for federated authentication.
- Security updates are coming for Windows App Platform and Frameworks, Windows Apps, Windows Input and Composition, Windows Office Media, Windows Fundamentals, Windows Cryptography, the Windows AI Platform, Windows Kernel, Windows Virtualization, and Windows Media.
- Windows Update also improves Microsoft has released an update directly to the Windows Update client to improve reliability. Any device running Windows 10 configured to receive updates automatically from Windows Update, including Enterprise and Pro editions, will be offered the latest Windows 10 feature update based on device compatibility and the Windows Update for Business deferral policy.This does not apply to long-term maintenance releases.
Known Issues
- User and system certificates might be lost when upgrading a device from Windows 10, version 1809 or later to a version Windows 10 later. Devices will only be affected if they have already installed any latest cumulative update (LCU) released on or after September 16, 2020, and then proceed to upgrade to a later version of Windows 10 from media or a later version of Windows 10. installation source that does not have an LCU released on October 13, 2020 or later integrated. This mainly occurs when managed devices are updated with outdated packages or media through an update management tool such as Windows Server Update Services (WSUS) or Microsoft Endpoint Configuration Manager.This can also occur when using outdated physical media or ISO images that do not have the latest updates integrated. For users experiencing this bug, it can be fixed within the uninstall window by going back to the previous version of Windows using the instructions here. The uninstall window can be 10 or 30 days depending on your environment settings and the version you are upgrading to. You will then need to upgrade to the later version of Windows 10 after the issue has been resolved in your environment. Note In the uninstall window, you can increase the number of days that you have to go back to the previous version of Windows 10 by using the DISM /Set-OSUninstallWindow command. You must make this change before the default uninstall window has expired. For more information, see DISM Operating System Uninstall Command Line Options.
- Devices with Windows installations created from custom offline media or a custom ISO image might have legacy Microsoft Edge removed by this update, but not automatically replaced by the new Microsoft Edge This issue only occurs when creating custom ISO or offline media images by sliding this update to the image without first installing the Standalone Servicing Stack Update (SSU) posted on or after March 29, 2021. To avoid this issue, make sure to first swipe the SSU released on or after March 29, 2021 on the custom offline media or ISO image before swiping the LCU. To do this with the SSU and LCU combo packs now used for Windows 10, version 20H2 and Windows 10, version 2004, you'll need to extract the SSU from the combo pack. Follow the steps below to extract the SSU usage:
- Extract the msu shell via this command line (using the package for KB5000842 as an example): expand Windows10.0-KB5000842-x64.msu /f:Windows10.0-KB5000842-x64 .cab
- Extract the SSU from the previously extracted cab via this command line: Expand Windows10.0-KB5000842-x64.cab /f: 3. You will then have the SSU cab, in this example named SSU-19041.903-x64.cab. Slide this file first to the offline image and then to the LCU.
If you have already encountered this issue by installing the operating system with affected custom media, you can mitigate it by directly installing the new Microsoft Edge If you need to deploy More widely about the new Microsoft Edge for business, read Download and deploy Microsoft Edge for business.
"If you have any of the Windows 10 versions mentioned, you can download the update using the usual route, that is,Settings > Update and Security > Windows Update or do it manually by downloading the corresponding installer in the 64-bit or 32-bit version."
More information | Microsoft