Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
patch-regressionwidely-deployed-product-advisoryendpoint-software-vulnerability

Microsoft Windows 11 Updates Trigger Boot Failures and Security-Driven Driver/Privilege Changes

Updated 3mo agoFirst seen Jan 30, 20263 sources

Microsoft attributed Windows 11 no-boot failures seen after installing the January 2026 cumulative update KB5074109 (Windows 11 24H2/25H2) to devices that had previously failed to install the December 2025 security update and were left in an “improper state” after rollback. Affected systems can crash on startup with a BSOD UNMOUNTABLE_BOOT_VOLUME; Microsoft said the issue appears limited to physical devices (no confirmed VM impact) and is working on a partial mitigation to prevent additional systems from entering a no-boot scenario, while continuing to investigate why some devices fail updates or end up unstable after rollback.

Separately, Microsoft’s recent Windows 11 servicing and security work included deliberately disabling legacy dial-up modem drivers (e.g., AGRSM64.SYS/AGRSM.SYS, SMSERL64.SYS/SMSERIAL.SYS) due to reported vulnerabilities including CVE-2023-31096 (EoP) and CVE-2025-24052 (stack-based buffer overflow), which can present risk even if the modem hardware is unused—at the cost of breaking connectivity for niche systems relying on those drivers. Microsoft also patched nine bypasses reported by Google Project Zero that could undermine the new Windows Administrator Protection feature by enabling silent admin privilege gains via legacy Windows/UAC behaviors (including a token/Logon Sessions-related technique involving NtQueryInformationToken and DOS device object directory creation), ahead of broader availability beyond Insider builds.

Share:
Microsoft Windows 11 Updates Trigger Boot Failures and Security-Driven Driver/Privilege Changes
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jan 30, 20265mo ago

Microsoft links January boot failures to failed December 2025 update

Microsoft said the Windows 11 boot failures were caused by systems left in an improper state after failed December 2025 security update installations and rollbacks. The company also said it was developing a partial mitigation to stop more devices from becoming unbootable during future update attempts.

Jan 29, 20265mo ago

Windows 11 cumulative updates disable legacy modem drivers

Recent Windows 11 cumulative updates intentionally decommissioned several legacy modem drivers, including Agere and Motorola soft-modem components, because of serious security vulnerabilities such as CVE-2023-31096 and CVE-2025-24052.

Jan 1, 20266mo ago

January 2026 cumulative update triggers Windows 11 boot failures

After installing the January 2026 cumulative update KB5074109 on Windows 11 24H2 and 25H2, some affected devices failed to boot and displayed a BSOD with the stop code UNMOUNTABLE_BOOT_VOLUME.

Administrator Protection becomes available in Windows Insider Canary builds

Earlier in January 2026, Microsoft made the new Windows Administrator Protection feature available to users in Windows Insider Canary builds, though it was not yet generally available.

Microsoft patches Administrator Protection bypass vulnerabilities

Shortly before Windows Administrator Protection became available to users earlier in January 2026, Microsoft patched multiple flaws, including a DOS device object directory issue involving shadow admin token impersonation.

Dec 1, 20257mo ago

Failed December 2025 Windows security update leaves some systems in improper state

During the December 2025 update cycle, some Windows 11 devices failed to install the security update and rolled back into an 'improper state.' Microsoft later said this condition set up affected systems for later boot failures.

Google Project Zero reports nine Administrator Protection bypass issues

In December 2025, Google Project Zero researcher James Forshaw reported nine vulnerabilities that could bypass Windows Administrator Protection, largely by exploiting known UAC-related behaviors to silently gain administrator privileges.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Affected products
2 linked
Windows 11Microsoft Office
Organizations
10 linked
Microsoft CorporationBleepingComputerAskWoodyASUSAppleBroadcomMediaTekMotorolaAgere SystemsGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.