New Windows Server updates trigger area controller crashes, reboots


Windows Server

The March 2024 Windows Server updates are inflicting some area controllers to crash and restart, based on widespread reviews from Windows directors.

Affected servers are freezing and rebooting due to a Local Security Authority Subsystem Service (LSASS) course of reminiscence leak launched with the March 2024 cumulative updates for Windows Server 2016 and Windows Server 2022.

LSASS is a Windows service that enforces safety insurance policies and handles consumer logins, entry token creation, and password modifications.

As many admins have warned, after putting in the KB5035855 and KB5035857 Windows Server updates launched this Patch Tuesday, area controllers with the newest updates would crash and reboot as a result of rising LSASS reminiscence utilization.

“Since set up of the march updates (Exchange in addition to common Windows Server updates) most of our DCs present continuously rising lsass reminiscence utilization (till they die),” one admin mentioned.

“We’ve had points with lsass.exe on area controllers (2016 core, 2022 with DE and 2022 core area controllers) leaking reminiscence as properly. To the purpose all area controllers crashed over the weekend and induced an outage,” one other one added.

“Our signs have been ballooning reminiscence utilization on the lsass.exe course of after putting in KB5035855 (Server 2016) and KB5035857 (Server 2022) to the purpose that every one bodily and digital reminiscence was consumed and the machine hung,” one admin instructed BleepingComputer.

“The Support rep says they count on official comms to be introduced from Microsoft quickly.”

Temporary workaround obtainable

Until Microsoft formally acknowledges this reminiscence leak subject, admins are suggested to uninstall the buggy Windows Server updates from their area controllers.

“Microsoft Support has beneficial that we uninstall the replace in the intervening time,” the identical admin instructed BleepingComputer.

To take away the troublesome updates, open an elevated command immediate by clicking the Start menu, typing ‘cmd,’ right-clicking the Command Prompt software, after which selecting ‘Run as Administrator.’

Next, run one of many following instructions, relying on what replace you’ve got put in in your Windows area controller:

wusa /uninstall /kb:5035855
wusa /uninstall /kb:5035857

Once uninstalled, you must also use the ‘Show or Hide Updates’ troubleshooter to cover the buggy replace so it is going to now not seem within the obtainable updates listing.

Microsoft addressed one other LSASS reminiscence leak affecting area controllers in December 2022, when affected servers would freeze and restart after putting in Windows Server updates launched in the course of the November 2022 Patch Tuesday.

In March 2022, Microsoft mounted yet one more LSASS crash, inflicting surprising Windows Server area controller reboots.

A Microsoft spokesperson couldn’t instantly present extra particulars when contacted by BleepingComputer earlier in the present day.


Please enter your comment!
Please enter your name here