Microsoft Releases Windows 10 KB5073724 Security Update Addressing Zero-Day Vulnerabilities
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Microsoft has released the KB5073724 extended security update for Windows 10, which addresses critical security issues, including three zero-day vulnerabilities. This update is part of the January 2026 Patch Tuesday and is available for users running Windows 10 Enterprise LTSC or those enrolled in the ESU program. Upon installation, Windows 10 will be updated to build 19045.6809, while Windows 10 Enterprise LTSC 2021 will update to build 19044.6809.
The KB5073724 update specifically fixes an actively exploited elevation of privileges vulnerability in the Agere modem drivers and a security flaw in the WinSqlite DLL. Additionally, it addresses the expiration of Secure Boot certificates, which are crucial for maintaining system security.
Implications of Secure Boot Certificate Expiration
Since June 2025, Microsoft has warned about the expiration of multiple Secure Boot certificates issued in 2011, which could lead to vulnerabilities if not updated. The update includes provisions for rolling out new Secure Boot certificates to eligible devices, ensuring that systems remain protected against potential threats.
As part of this update, Microsoft has removed specific modem drivers, including agrsm64.sys and agrsm.sys, which means that hardware dependent on these drivers will no longer function in Windows. Users should be aware of this change and check their hardware compatibility.
Microsoft has assured users that there are no known issues with this update, emphasizing its importance in maintaining system security. Organizations and users should prioritize installing this update to mitigate risks associated with the identified vulnerabilities.
- KB5073724: This update addresses three zero-day vulnerabilities and includes fixes for 114 security flaws.
- Agere modem drivers: The update removes specific modem drivers, impacting hardware functionality.
- Secure Boot: New certificates are being rolled out to maintain system security as older certificates expire.
- WinSqlite DLL: The update fixes a security flaw in this critical Windows component.
Key Takeaways
- Check for updates in Windows 10 to ensure KB5073724 is installed promptly.
- Review hardware compatibility, especially if using devices dependent on the removed Agere modem drivers.
- Monitor for any notifications regarding Secure Boot certificate updates to maintain system security.
- Stay informed about future updates from Microsoft, as they may address additional vulnerabilities.
- Consider enrolling in the ESU program if using Windows 10 Enterprise LTSC for continued support.
Key Terms & Concepts
- Zero-Day Vulnerability: In this article, a zero-day vulnerability refers to a security flaw that is exploited before the vendor has issued a fix.
- Secure Boot: Secure Boot is a security standard that ensures only trusted software can run during the boot process.
- Elevation of Privileges: Elevation of privileges is a type of security vulnerability that allows an attacker to gain higher access rights than intended.
- Windows 10 Enterprise LTSC: Windows 10 Enterprise LTSC is a version of Windows designed for businesses that require long-term support and stability.
- ESU Program: The ESU program is an Extended Security Update program that provides security updates for older versions of Windows.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.