Microsoft has confirmed that the November 2025 non-security preview update KB5070311 and subsequent patches for Windows 11 (versions 24H2 and 25H2) and Windows Server 2025 are causing RemoteApp connection failures in Azure Virtual Desktop (AVD) environments. This issue primarily impacts enterprise users who rely on RemoteApp to stream individual applications, while full desktop sessions and personal devices running Windows Home or Pro are largely unaffected. The disruption stems from changes to Remote Desktop Protocol (RDP) shell handling introduced by the update, leading to widespread difficulties for organizations dependent on virtualized workloads.
To address the problem, Microsoft has provided two main mitigation options: a manual registry edit requiring administrative privileges, and the use of Known Issue Rollback (KIR), which automatically reverts the problematic update for Pro and Enterprise devices. Enterprise administrators managing updates via IT policies can also deploy a targeted Group Policy using a specific MSI package. Microsoft has urged affected organizations to implement these workarounds promptly to restore RemoteApp functionality and minimize operational impact.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft confirmed in December 2025 that recent updates were causing the Azure Virtual Desktop RemoteApp failures. The company provided a manual registry workaround and Known Issue Rollback guidance, including Group Policy deployment options for managed environments, while stating that a permanent fix is still being developed.
Starting with the November 2025 non-security preview update KB5070311, Windows 11 24H2/25H2 and Windows Server 2025 devices in Azure Virtual Desktop environments began experiencing RemoteApp connection failures. The issue affected enterprise RemoteApp sessions, while full desktop sessions and most Home or Pro devices were not impacted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.