Applies ToWindows 10, version 1709, all editions

Release Date:

15/10/2019

Version:

OS Build 16299.1481

Reminder March 12 and April 9 were the last two Delta updates for Windows 10, version 1709. Security and quality updates will continue to be available via the express and full cumulative update packages. For more information on this change please visit our blog.

Reminder Windows 10, version 1709, reached end of service on April 9, 2019 for devices running Windows 10 Home, Pro, Pro for Workstation, and IoT Core editions. These devices will no longer receive monthly security and quality updates that contain protection from the latest security threats. To continue receiving security and quality updates, Microsoft recommends updating to the latest version of Windows 10.

IMPORTANT Windows 10 Enterprise, Education, and IoT Enterprise editions will continue to receive servicing for 12 months at no cost per the lifecycle announcement on October 2018.

ePub support ended in Microsoft Edge

Microsoft Edge has ended support for e-books that use the .epub file extension. For more information, see Download an ePub app to keep reading e-books.

For more information about the various types of Windows updates, such as critical, security, driver, service packs, and so on, please see the following article.

Highlights

  • Updates an issue that causes a system to stop working during the Windows upgrade process.

Improvements and fixes

This non-security update includes quality improvements. Key changes include:

  • Updates time zone information for Norfolk Island, Australia.

  • Updates time zone information for the Fiji Islands.

  • Addresses an issue that causes a query request of the Win32_LogonSession class for the StartTime to display the value of the epoch (for example, 1-1-1601 1:00:00) instead of the actual logon time.

  • Addresses an issue that causes a system to stop working during the Windows upgrade process. The Stop error “SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)” appears in the Transmission Control Protocol/Internet Protocol (TCPIP).

  • Addresses an issue that prevents the BitLocker recovery key from being successfully backed up to Azure Active Directory.

  • Addresses an issue that fails to include the full file hash as part of the Event Log entry during auditing events for Windows Defender Application Control (WDAC).

  • Addresses an issue in which Microsoft AppLocker may prevent an application from running or log a false positive error instead of running the application.

  • Addresses an issue that causes the WDAC policy to become too restrictive when you enable the WDAC Group Policy setting for Script Enforcement or Constrained Language Mode.

  • Addresses an issue that prevents netdom.exe from displaying the new ticket-granting ticket (TGT) delegation bit for the display or query mode.

  • Addresses an issue that may cause high CPU usage when many windows are open and Background Application Manager runs a periodic background scan. Additionally, the desktop may become unresponsive. To turn off this scan, set the following registry key:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BamThrottling

Name: DisableWindowHinting

Type: REG_DWORD

Value: 1 

  • Addresses an issue that sometimes causes the Resilient File System (ReFS) to stop working.

  • Addresses an issue with evaluating the compatibility status of the Windows ecosystem to help ensure application and device compatibility for all updates to Windows.

  • Addresses an issue with a race condition between the volume mount process (within fileinfo.sys) and the deregistration of filter notifications that causes the operating system to stop working on certain virtual machines. The error code is “0x7E.”

  • Facilitates the configuration of devices that are managed by mobile device management (MDM) settings, which are created by ADMX ingestion. You can update a previously ingested ADMX file with a newer version, and you are not required to delete the previous ADMX file. This solution applies to all applications that use ADMX ingestion.

If you installed earlier updates, only the new fixes contained in this package will be downloaded and installed on your device.

Known issues in this update

Symptom

Workaround

Certain operations, such as rename, that you perform on files or folders that are on a Cluster Shared Volume (CSV) may fail with the error, “STATUS_BAD_IMPERSONATION_LEVEL (0xC00000A5)”. This occurs when you perform the operation on a CSV owner node from a process that doesn’t have administrator privilege.

Do one of the following:

  • Perform the operation from a process that has administrator privilege.

  • Perform the operation from a node that doesn’t have CSV ownership.

Microsoft is working on a resolution and will provide an update in an upcoming release.

When setting up a new Windows device during the Out of Box Experience (OOBE), you might be unable to create a local user when using Input Method Editor (IME). This issue might affect you if you are using the IME for Chinese, Japanese, or Korean languages.

Note This issue does not affect using a Microsoft Account during OOBE.

This issue is resolved in KB4534318.

How to get this update

Before installing this update

Microsoft strongly recommends you install the latest servicing stack update (SSU) for your operating system before installing the latest cumulative update (LCU). SSUs improve the reliability of the update process to mitigate potential issues while installing the LCU. For more information, see Servicing stack updates.

If you are using Windows Update, the latest SSU (KB4521860) will be offered to you automatically. To get the standalone package for the latest SSU, search for it in the Microsoft Update Catalog.

Install this update

Release Channel

Available

Next Step

Windows Update or Microsoft Update

Yes

Go to Settings > Update & Security > Windows Update and select Check for updates.

Microsoft Update Catalog

Yes

To get the standalone package for this update, go to the Microsoft Update Catalog website.

Windows Server Update Services (WSUS)

No

You can import this update into WSUS manually. See the Microsoft Update Catalog for instructions.

 

File information

For a list of the files that are provided in this update, download the file information for cumulative update 4520006.

Need more help?

Want more options?

Explore subscription benefits, browse training courses, learn how to secure your device, and more.

Communities help you ask and answer questions, give feedback, and hear from experts with rich knowledge.