KB5061059 for Windows Server 2012 – ESU for June 2025

KB5061059 is the ESU Monthly Rollup Update for Windows Server 2012. It was released on 10 June 2025 under the ‘Patch Tuesday’ program.

Salient points

  • KB5061059 supersedes KB5058451 released in May 2025.
  • KB5061059 requires a new Servicing Stack Update to be installed prior to installing the main monthly rollup update. KB5058530 is the SSU corresponding to KB5061059 Without the installation of KB5058530, the ESU KB5061059 cannot be installed. For WSUS administrators, KB5058530 needs to be approved before KB5061059 will be fetched and deployed automatically.
  • If you install language pack after installing KB5061059, you would need to reinstall the security update. All language pack installations must be completed before installing the monthly rollup update on Windows Server 2012.
  • KB5061059 is an Extended Security Update. A valid subscription key to the ESU program is required before installing the monthly rollup update.
  • You will also need to install KB5060996 IE Cumulative Update for patching Internet Explorer 11 on Windows Server 2012.
  • Windows Server 2012 is impacted by 21 security vulnerabilities reported in June 2025 security bulletin. 1 security vulnerability impacts Internet Explorer 11.
  • Three of these vulnerabilities have CRITICAL severity.
  • Two zero-day vulnerabilities affect Windows Server 2012 and Windows Server 2012 Server Core installation.

Servicing Stack Update KB5058530

The Servicing Stack Update for Windows Server 2012 for June 2025 is KB5058530. It corresponds to KB5061059.

For automated deployments of KB5061059 through the Windows Update program, the Servicing Stack Update KB5058530 is offered for installation as part of the installation process of the monthly rollup update KB5061059. No further action is needed to install KB5058530 for automated installations of KB5061059.

The Servicing Stack Update file is a small file of 10 MB. Upon installation, it would not cause server reboot.

Once the SSU is installed, you can proceed with the installation of the main monthly rollup update KB5052020.

Download KB5061059

You can download the monthly rollup update KB5061059 for Windows Server 2012 from the Windows Update Catalog page shared below:

We would reiterate that you need a valid ESU program subscription before you could install the ESU KB5061059 on Windows Server 2012.

Zero-day Vulnerabilities

Two security vulnerabilities with zero-day threat levels affect Windows Server 2016 and Windows Server 2016 Server Core installation.

CVETitleSeverityCVSSType
CVE-2025-33053Web Distributed Authoring and Versioning (WEBDAV)Important8.8Remote Code Execution
CVE-2025-33073Windows SMB ClientImportant8.8EoP

Critical vulnerabilities

There are 21 reported security vulnerabilities in Windows Server 2012 for June 2025. The 3 CRITICAL vulnerabilities affecting Windows Server 2012 are shared below.

CVETitleCVSSType
CVE-2025-33070Windows Netlogon8.1EoP
CVE-2025-33071Windows KDC Proxy Service (KPSSVC)8.1RCE
CVE-2025-32710Windows Remote Desktop Services8.1RCE

KB5061059 – Changelog

Since this is an ESU, the focus remains on securing the Windows Server 2012 deployments. The following changes have been reported for KB5061059:

  • [Internal Windows OS] Miscellaneous security improvements were made to internal Windows OS functionality. No additional issues are documented for this release.

KB5060996 for Internet Explorer

You will also need to install KB5060996 Internet Explorer Cumulative Update. This Internet Explorer update is for Internet Explorer version 11.

KB5060096 is additional to the cumulative ESU update KB5061059. It is also an ESU or Extended Security Update and needs to be installed on Windows Server 2012 for full security coverage.

For automated installations through the WSUS program, IE Cumulative Update KB5060096 will be automatically installed on the Windows Server 2012 once you have authorized KB5061059.

For manual deployments, you can download the IE Cumulative ESU update KB5060996 from the following catalog link:

Rajesh Dhawan

Rajesh Dhawan is a technology professional who loves to write about Cyber-security events and stories, Cloud computing and Microsoft technologies. He loves to break complex problems into manageable chunks of meaningful information.