KB5052042 ESU for Windows Server 2012 R2

KB5052042 is the ESU Monthly Rollup Update for Windows Server 2012 R2. It was released on 11 February 2025 under the ‘Patch Tuesday’ program.

Salient points

  • KB5052042 supersedes KB5050048 released in January 2024.
  • KB5052042 requires a Servicing Stack Update to be installed prior to installing the main monthly rollup update. KB5052108 is the SSU corresponding to KB5052042.
  • If you install language pack after installing KB5052042, you would need to reinstall the security update once again. All language pack installations must be completed before installing the monthly rollup update on Windows Server 2012 R2.
  • KB5052042 is an Extended Security Update. A valid subscription key to the ESU program is required before installing the monthly rollup update.
  • You will also need to install KB5051972 IE Cumulative Update for Internet Explorer 11 on Windows Server 2012 R2. KB5051972 is an ESU or Extended Security Update.
  • Windows Server 2012 R2 is impacted by 24 security vulnerabilities reported in February 2025 security bulletin. One of these vulnerabilities have a CRITICAL severity.
  • There is a CRITICAL vulnerability with CVSS score of 8.1. CVE-2025-21376 impacts Windows Lightweight Directory Access Protocol (LDAP) and could lead to Remote Code Execution attacks. This vulnerability affects Windows Server 2012.
  • Two zero-day vulnerabilities affect Windows Server 2012 R2 and Windows Server 2012 Server Core installation.
  • CVE-2025-21377 (zero-day) is an NTLM Hash Disclosure Spoofing with CVSS score of 6.5.
  • CVE-2025-21418 (zero-day) is an Elevation of Privilege Vulnerability affecting Windows Ancillary Function Driver for WinSock. It has a CVSS score of 7.8.

Servicing Stack Update KB5052108

The Servicing Stack Update for Windows Server 2012 R2 for February 2025 is KB5052108. It corresponds to KB5052042.

For automated deployments of KB5052042 through the Windows Update program, the Servicing Stack Update KB5052108 is offered for installation as part of the installation process of the monthly rollup update KB5052042. No further action is needed to install KB5052108 for automated installations of KB5052042.

WSUS administrators need to authorize or approve KB5052108 before KB5052042 is fetched and installed in WSUS.

If you choose to deploy KB5052042 manually, you need to download and install KB5052108 on the Windows Server 2012 R2.

The Servicing Stack Update file is a small file of 10.5 MB. Upon installation, it would not cause server reboot. Once the SSU is installed, you can proceed with the installation of the main monthly rollup update KB5052042.

Download KB5052042

You can download the monthly rollup update KB5052042 for Windows Server 2012 R2 from the Windows Update Catalog page shared below:

We would reiterate that you need a valid ESU program subscription before you could install the ESU KB5052042 on Windows Server 2012 R2.

KB5052042 – Changelog

Since this is an ESU, the focus remains on securing the Windows Server 2012 R2 deployments. The following changes have been reported for KB5052042:

  • [USB cameras] Fixed: Your device does not recognize the camera is on. This issue occurs after you install the January 2025 security update.
  • [Digital/Analog converter (DAC)] Fixed: You might experience issues with USB audio devices. This is more likely when you use a DAC audio driver based on USB 1.0. USB audio devices might stop working, which stops playback.

KB5051972 for Internet Explorer

You will also need to install KB5051972 Internet Explorer Cumulative Update on Windows Server 2012 R2. This Internet Explorer update is for Internet Explorer version 11.

KB5051972 is additional to the cumulative ESU update KB5052042. It is also an ESU or Extended Security Update and needs to be installed on Windows Server 2012 R2 for full security coverage.

For automated installations through the WSUS program, IE Cumulative Update KB5051972 will be automatically installed on the Windows Server 2012 R2 once you have authorized KB5052042.

For manual deployments, you can download the IE Cumulative ESU update KB5051972 from the following catalog link:

Rajesh Dhawan

Rajesh Dhawan is a technology professional who loves to write about Cyber-security events and stories, Cloud computing and Microsoft technologies. He loves to break complex problems into manageable chunks of meaningful information.