News

Windows Update Bug Crashes Domain Controllers

Reading time: 1 Minute Read
Roy Ludmir
Updated on: September 15, 2025
Windows Update Bug Crashes Domain Controllers

Windows Patch Tuesday Updates

Windows administrators have cautioned that after applying the KB5035855 and KB5035857 updates, released as part of March 2024 Patch Tuesday for Windows Server 2016 and Windows Server 2022, domain controllers running the updated versions of Windows Server may experience crashes and reboots. Affected servers are freezing and rebooting stemming from a memory leak in the Local Security Authority Subsystem Service (LSASS), leading to continually increasing memory usage over time.

One user on Reddit’s Patch Tuesday Megathread wrote “We’ve had issues with lsass.exe on domain controllers (2016 core, 2022 with DE and 2022 core domain controllers) leaking memory as well. To the point all domain controllers crashed over the weekend and caused an outage.”

One comment on Microsofts TechCommunity wrote ‘We deinstalled the Windows Server March 2024 update from an affected domain controller and the issue was gone instantly!”

While vulnerability patches are crucial for server security, automated server hardening offers a more proactive approach.  Patching addresses discovered weaknesses, but hardening reduces the attack surface overall by minimizing potential entry points from the start. This makes servers less vulnerable in the first place, lessening reliance on reactive patching.

Short-term Resolution Offered

BleepingComputer has quoted an admin stating Microsoft Support has recommended to uninstall the update for the time being and provided instructions on how to do it.

To remove Microsoft’s updates:

Open an elevated command prompt by clicking the Start menu > type ‘cmd,’ > right-clicking the Command Prompt application > choose ‘Run as Administrator.’

Depending on the update you installed on your Windows domain controller, run one of the following commands:

wusa /uninstall /kb:5035855

wusa /uninstall /kb:5035857

Once uninstalled, use the ‘Show or Hide Updates’ troubleshooter to hide the recent update so it will no longer appear in the available updates list.

cis certified

Roy Ludmir
Roy Ludmir is a cybersecurity entrepreneur and CEO with over 15 years of experience driving product innovation and sales growth in the security industry. He is highly skilled in CIS Benchmarks, baseline hardening, and vulnerability management, helping organizations strengthen defenses and meet compliance requirements. With a unique blend of executive leadership and deep technical expertise, he bridges business strategy with practical security solutions.

Related Articles

About Us

Established in 2001, CalCom is the leading provider of server hardening solutions that help organizations address the rapidly changing security landscape, threats, and regulations. CalCom Hardening Suite (CHS) is a security baseline hardening solution that eliminates outages, reduces operational costs, and ensures a resilient, constantly hardened, and monitored server environment.

More about us
Background Shape
About Us

Stay Ahead with Our Newsletter

Get the latest insights, security tips, and exclusive resources straight to your inbox every month.

    Ready to simplify compliance?

    See automated compliance in action—book your demo today!