Microsoft has fixed a critical Windows 11 vulnerability without requiring a reboot.
Microsoft has released an unscheduled KB5084597 update for Windows 11 that addresses vulnerabilities in the Routing and Remote Access service. The patch is being distributed only to devices that support hotpatching and does not require a restart.
Crius
Microsoft has released an out-of-band Windows 11 update, KB5084597, to address a vulnerability in the Routing and Remote Access Service (RRAS). For devices that support hotpatch technology, installing this update does not require a reboot.
Main Details About the KB5084597 Update
This update is intended for Windows 11 versions 25H2 and 24H2 and focuses on fixing a vulnerability in the RRAS management tool. After installation, systems are updated to OS builds 26200.7982 and 26100.7982. The update package was published on March 13, 2026.
KB5084597 resolves a vulnerability where, when connecting to a malicious remote server, an attacker could disrupt the tool’s operation or execute code on the device. The update addresses vulnerabilities CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111.
Distribution and Installation Features
This patch is not a general update for all users. It is distributed only to devices with hotpatch support and does not require any action from PCs receiving standard Windows updates. On compatible systems, the update is downloaded automatically via Windows Update and takes effect without the need for a restart.
According to Microsoft documentation, hotpatch updates are released monthly to improve security compliance and reduce the number of failures. Hotpatch requires Windows Autopatch, and the device must be registered under the appropriate quality update policy.
Requirements for Arm64 Devices
Hotpatch is now available for Windows 11 25H2 and 24H2 devices on Arm64, provided certain conditions are met: Windows 11 Enterprise is installed, Intune is used with a hotpatch policy, the appropriate license is in place, virtualization-based security is enabled, and hybrid PE compilation is disabled.
Target Audience and Benefits
KB5084597 is primarily intended for corporate IT administrators and managed devices, not for home users. For such systems, the update demonstrates the advantages of hotpatch technology—security fixes can be applied immediately, automatically, and without a reboot, helping to avoid work interruptions.
Additional Information
At the time of publication, no known issues with the KB5084597 update have been reported. This is especially important since out-of-band Windows updates affecting network security components often raise deployment concerns.
To report any potential issues with the update, you can use the Feedback Hub app.
