Every supported version of Windows 10 just received a new update

Dell XPS 13 9300
Dell XPS 13 9300 (Image credit: Daniel Rubino / Windows Central)

What you need to know

  • Every supported version of Windows 10 received an update on Patch Tuesday.
  • The updates improve security in several areas.
  • You can grab the updates for Windows 10 versions 1909, 2004, and 20H2 now.

Patch Tuesday just rolled by, and that means updates for Windows 10. Each supported version of Windows 10 has a new update, including versions 1909, 2004, and 20H2.

If your PC is on Windows 10 version 20H2 or 2004, you'll receive KB5001330. The update brings the build number to 19042.928 for 20H2 and 19041.928 for 2004. You can manually grab the update from the Microsoft Update Catalog. Here's what's new, as found in its changelog:

Highlights

  • Updates to improve security when Windows performs basic operations.
  • Updates to improve security when using input devices such as a mouse, keyboard, or pen.

This security update includes quality improvements. Key changes include:

  • Addresses an issue in which a principal in a trusted MIT realm fails to obtain a Kerberos service ticket from Active Directory domain controllers (DC). This occurs on devices that installed Windows Updates that contain CVE-2020-17049 protections and configured PerfromTicketSignature to 1 or higher. These updates were released between November 10, 2020 and December 8, 2020. Ticket acquisition also fails with the error, "KRB_GENERIC_ERROR", if callers submit a PAC-less Ticket Granting Ticket (TGT) as an evidence ticket without providing the USER_NO_AUTH_DATA_REQUIRED flag.
  • Addresses an issue with security vulnerabilities identified by a security researcher. Because of these security vulnerabilities, this and all future Windows updates will no longer contain the RemoteFX vGPU feature. For more information about the vulnerability and its removal, see CVE-2020-1036 and KB4570006. Secure vGPU alternatives are available using Discrete Device Assignment (DDA) in Windows Server LTSC releases (Windows Server 2016 and Windows Server 2019) and Windows Server SAC releases (Windows Server, version 1803 and later versions).
  • Addresses a potential elevation of privilege vulnerability in the way Azure Active Directory web sign-in allows arbitrary browsing from the third-party endpoints used for federated authentication. For more information, see CVE-2021-27092 and Policy CSP - Authentication.
  • Security updates to Windows App Platform and Frameworks, Windows Apps, Windows Input and Composition, Windows Office Media, Windows Fundamentals, Windows Cryptography, the Windows AI Platform, Windows Kernel, Windows Virtualization, and Windows Media.

If your PC is on Windows 10 version 1909, you'll receive KB5001337, which brings systems to build 18363.1500. You can manually download from the Microsoft Update Catalog. Note that this version of Windows 10 will only be supported for one more month. Here's what's new, as seen in its changelog:

Highlights

  • Updates to improve security when Windows performs basic operations.
  • Updates to improve security when using input devices such as a mouse, keyboard, or pen.

This security update includes quality improvements. Key changes include:

  • Addresses an issue in which a principal in a trusted MIT realm fails to obtain a Kerberos service ticket from Active Directory domain controllers (DC). This occurs on devices that installed Windows Updates that contain CVE-2020-17049 protections and configured PerfromTicketSignature to 1 or higher. These updates were released between November 10, 2020 and December 8, 2020. Ticket acquisition also fails with the error, "KRB_GENERIC_ERROR", if callers submit a PAC-less Ticket Granting Ticket (TGT) as an evidence ticket without providing the USER_NO_AUTH_DATA_REQUIRED flag.
  • Addresses an issue with security vulnerabilities identified by a security researcher. Because of these security vulnerabilities, this and all future Windows updates will no longer contain the RemoteFX vGPU feature. For more information about the vulnerability and its removal, see CVE-2020-1036 and KB4570006. Secure vGPU alternatives are available using Discrete Device Assignment (DDA) in Windows Server LTSC releases (Windows Server 2016 and Windows Server 2019) and Windows Server SAC releases (Windows Server, version 1803 and later versions).
  • Addresses a potential elevation of privilege vulnerability in the way Azure Active Directory web sign-in allows arbitrary browsing from the third-party endpoints used for federated authentication. For more information, see CVE-2021-27092 and Policy CSP - Authentication.
  • Security updates to Windows App Platform and Frameworks, Windows Apps, Windows Input and Composition, Windows Office Media, Windows Fundamentals, Windows Cryptography, the Windows AI Platform, Windows Hybrid Cloud Networking, the Windows Kernel, Windows Virtualization, and Windows Media.

If you're running an older version of Windows 10 that's on extended support, you can also find the most recent update in the Microsoft Update Catalog.

Sean Endicott
News Writer and apps editor

Sean Endicott brings nearly a decade of experience covering Microsoft and Windows news to Windows Central. He joined our team in 2017 as an app reviewer and now heads up our day-to-day news coverage. If you have a news tip or an app to review, hit him up at sean.endicott@futurenet.com.