KB5004945 for Windows 10 21H1, 20H2, 2004 to fix printing vulnerability

Out of Band band update KB5004945 for Windows 10 21H1, 20H2, 2004 changelog, direct download link, and ways to install.


A security update is rolling out today on 06/07/2021!  Windows 10 2004, 20H2, and 21H1 have received a patch with some considerable fixes for the printer vulnerability issue. KB5004945  is the out of band update having some potential workarounds for the critical issue. As you might know, this vulnerability exists in printer spooler service and is titled as PrintNightmare. The system can not stop attackers from running arbitrary codes through remote code execution (RCE). This is placed under CVE-2021-34527 and Microsoft is keeping an eye on the situation.

The printing issue is being tracked and investigated this out-of-band update brings 2 possible workarounds to mitigate the damage. The release will change the version of Windows 21H1, 20H2, and 2004 to 19043.1083, 19042.1083, and 19041.1083 respectively. This is a mandatory update and will be downloaded automatically without notifying you.

KB5004945 Windows 10 21H1, 20H2, and 2004 to fix printing vulnerability

Here is the changelog –

Improvements and bug fixes

This patch addresses a RCE exploit existing in the Print Spooler service, termed PrintNightmare, under CVE-2021-34527. Subsequent to installing this rollout and further updates, non-admin users will be only able to install the printer drivers which is signed in to a printer server. However, administrators can install both the unsigned as well as signed drivers. Signed drivers are satisfied by root certificates in the Trusted Root Certification Authorities trust of the system. The tech giant suggests that you should install this update on all supported client and server OS, starting with devices that currently host the print server role. Moreover, you can change the RestrictDriverInstallationToAdministrators regedit setting to prevent non-administrators from installing signed printer drivers on a print server. To know more go to – –KB5005010.

Known issues

Symptoms Workaround
Furigana characters don’t return with correct characters in Kanji characters in Japanese IME. Therefore, you might have to enter the Furigana characters manually.

Remark –The affected applications are using ImmGetCompositionString() function.

They are trying to have a resolution and this may be out in a forthcoming update.
When custom ISO or Custom offline media creates the installation it is not capable to replace Microsoft Edge Legacy with the chromium version. However, it removes  the legacy. You confront this when ISO or custom offline media is generated by slipstreaming this update into the image without having prior installed the SSU rolled out 29/03/2021 or later. If don’t want to find this problem,  slipstream the SSU into ISO or custom offline media before slipstreaming the Cumulative patch. In case you are on v2004 04 20H2, extract the SSU from the combined package. Pursue the instructions –

  1. In order to extract cab from MSU through below command (using the package for KB5001330 as an example):
    expand Windows10.0-KB5001330-x64.msu /f:Windows10.0-KB5001330-x64.cab <destination path>
  2. Extract the Servicing Stack Update from the previously extracted cab through command :
    expand Windows10.0-KB5001330-x64.cab /f:* <destination path>
  3. You will then have the Servicing Stack Update cab here as SSU-19041.964-x64.cab. Finally, Slipstream this file into an offline image first, then into Cumulative Update.

Alternatively, there is a simple method; only install – new Microsoft Edge or Download and deploy Microsoft Edge for business.

How to download KB5004945 and install

Since SSU is folded into cumulative update now so go directly to the following methods to install the patch –

1. Through Windows update

  1. Press the – Winkey.
  2. Type – updates.
  3. Hit the – Enter key.
  4. When Setting page prompts, you will notice that the update is downloaded is asking you to Restart now; select it.
  5.  Otherwise, click the – Check for upddates.
  6. Lastly, hit – Restart now.

2. Using Microsoft update catalog

Here is KB5004945 direct download link – Windows update catalog. Click it.

  1. Find the correct file and click – Download.
  2. A separate page comes out, click the lone link there.
  3. As the downloading is completed, double click the .MSU file.
  4. Follow the on-screen instructions until the out-of-band update is fully installed.

For more knowledge about the installation method, you can read – How to Download and Install Update from Microsoft update catalog on Windows 10.

That’s all!!

Sharing is caring    Share Whatsapp

Topics:  Windows update
About Sunita
Love to play with Windows 11 and 10. Suggestion - Going for Registry change or system files edit then remember to take a backup or create a restore point before Starting.