KB5066873 ESU for Windows Server 2012 R2 – October 2025

KB5066873 is the ESU Monthly Rollup Update for Windows Server 2012 R2. It was released on 14 October 2025 under the ‘Patch Tuesday’ program.

Salient points

  • KB5066873 supersedes KB5065507 released in September 2025.
  • KB5066873 requires a Servicing Stack Update to be installed prior to installing the main monthly rollup update. KB5066794 is the SSU corresponding to KB5066873.
  • If you install language pack after installing KB5066873, you would need to reinstall the security update once again. All language pack installations must be completed before installing the monthly rollup update on Windows Server 2012 R2.
  • KB5066873 is an Extended Security Update. A valid subscription key to the ESU program is required before installing the monthly rollup update.
  • Windows Server 2012 R2 is impacted by 51 security vulnerabilities reported in October 2025 security bulletin. 2 of these vulnerabilities are ‘CRITICAL’.
  • Three zero-day vulnerability affects Windows Server 2012 R2 and Windows Server 2012 Server Core installation.

Servicing Stack Update KB5066794

The Servicing Stack Update for Windows Server 2012 R2 for October 2025 is KB506794. It corresponds to KB5066873 ESU.

For automated deployments of KB5066873 through the Windows Update program, the Servicing Stack Update KB5066794 is offered for installation as part of the installation process of the monthly rollup update KB5066873. No further action is needed to install KB5065767 for automated installations of KB5066873.

WSUS administrators need to authorize or approve KB5066794 before KB5066873 is fetched and installed in WSUS.

If you choose to deploy KB5066873 manually, you need to download and install KB5066794 on the Windows Server 2012 R2.

The Servicing Stack Update file is a small file of 10.6 MB. Upon installation, it would not cause server reboot. Once the SSU is installed, you can proceed with the installation of the main monthly rollup update KB5063950.

Download KB5066873

You can download the monthly rollup update KB5066873 for Windows Server 2012 R2 from the Windows Update Catalog page shared below:

We would reiterate that you need a valid ESU program subscription before you could install the ESU KB5066873 on Windows Server 2012 R2.

Zero-day Vulnerabilities

Three security vulnerability with zero-day threat levels affect Windows Server 2012 R2 and Windows Server 2012 R2 Server Core installation.

VulnerabilityCVSS ScoreSeverityDescription
CVE-2025-249907.8ImportantElevation of Privileges affecting Windows Agere Modem Driver
CVE-2025-478274.6ImportantSecure Boot bypass in IGEL OS before 11 
CVE-2025-592307.8ImportantElevation of Privileges vulnerabity in remote access connection manager

Critical vulnerabilities

There are 51 reported security vulnerabilities in Windows Server 2012 R2 for October 2025. The 2 CRITICAL vulnerabilities affecting Windows Server 2012 R2 are shared below.

VulnerabilityCVSSDescription
CVE-2025-592879.8Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
CVE-2016-95354.0LibTIFF Heap Buffer Overflow Vulnerability 

KB5066873 – Changelog

Since this is an ESU, the focus remains on securing the Windows Server 2012 R2 deployments. The following changes have been reported for KB5066873:

  • [Internal Windows OS] Miscellaneous security improvements were made to internal Windows OS functionality.
  • [Stability issue] Fixed: This update addresses an issue observed in rare cases after installing the May 2025 security update and subsequent updates causing devices to experience stability issues. Some devices became unresponsive and stopped responding in specific scenarios. ​​​​​​
  • [Fax modem driver] This update removes the ltmdm64.sys driver. Fax modem hardware dependent on this specific driver will no longer work in Windows.

Internet Explorer Cumulative Update – KB5066840

To secure the Windows Server 2012 R2, you also need to patch Internet Explorer 11 with the latest cumulative update. KB5066840 is the cumulative update for Internet Explorer released on 14 October 2025.

You can download the IE Cumulative Update for Windows Server 2012 R2 from the link shared below:

Download Cumulative Update for Internet Explorer – KB5066840 (54.9 MB)

Rajesh Dhawan

Simplifying technology, one step at a time.