Microsoft fixes WSUS bug blocking May Windows security updates

Microsoft has resolved a known issue preventing managed devices from receiving the May 2021 Patch Tuesday Windows security updates.

"When checking for updates within Windows Server Update Services (WSUS) or Microsoft Endpoint Configuration Manager and managed devices that connect to these servers," this month's security updates "might not be available or offered," as Microsoft explained on the Windows Health Dashboard.

"This might also affect Security Only and Internet Explorer Cumulative Rollups, on platforms that receive these types of updates."

The known issue impacted both client and server platforms, from Windows 7 SP1 and Windows Server 2008 SP2 up to the latest versions, Windows 10 20H2 and Windows Server 20H2.

The list of Windows cumulative updates blocked by this known issue includes:

  • KB5003173 (Windows 10/Server, version 20H2/2004)
  • KB5003169 (Windows 10/Server, version 1909)
  • KB5003171 (Windows 10, version 1809 and Windows Server 2019)
  • KB5003174 (Windows 10, version 1803)
  • KB5003197 (Windows 10, version 1607 and Windows Server 2016)
  • KB5003172 (Windows 10, version 1507)
  • KB5003209 (Windows 8.1 and Windows Server 2012 R2)
  • KB5003208 (Windows Server 2012)
  • KB5003233 (Windows 7 and Windows Server 2008 R2 SP1)
  • KB5003210 (Windows Server 2008 SP2)

Security updates might be delayed in some regions

Microsoft has resolved the known issue on the service-side, and the updates should start rolling out to affected devices in managed environments.

"If you initiate a synchronization cycle and are still not being offered the updates, please check again soon," Microsoft added. "There might be a slight delay as it propagates to all servers in all regions."

During this month's Patch Tuesday, Microsoft fixed 55 vulnerabilities, four classified as Critical, 50 as Important, and one as Moderate, as well as three zero-day vulnerabilities publicly disclosed but not known to be used in attacks.

These are the three vulnerabilities Microsoft said were publicly disclosed but not exploited in the wild before the May 2021 security updates were released:

  • CVE-2021-31204 - .NET and Visual Studio Elevation of Privilege Vulnerability
  • CVE-2021-31207 - Microsoft Exchange Server Security Feature Bypass Vulnerability
  • CVE-2021-31200 - Common Utilities Remote Code Execution Vulnerability

Yesterday, together with cumulative updates with security fixes for Windows 10 2004 and 20H2, Microsoft also started rolling out new cumulative updates for all supported Windows versions.

Related Articles:

Microsoft says April Windows updates break VPN connections

Microsoft fixes bug behind incorrect BitLocker encryption errors

Recent Windows updates break Microsoft Connected Cache delivery

Microsoft: Recent updates cause Sysprep Windows validation errors

Microsoft fixes Windows Sysprep issue behind 0x80073cf2 errors