Microsoft attributed Windows 11 no-boot failures seen after installing the January 2026 cumulative update KB5074109 (Windows 11 24H2/25H2) to devices that had previously failed to install the December 2025 security update and were left in an “improper state” after rollback. Affected systems can crash on startup with a BSOD UNMOUNTABLE_BOOT_VOLUME; Microsoft said the issue appears limited to physical devices (no confirmed VM impact) and is working on a partial mitigation to prevent additional systems from entering a no-boot scenario, while continuing to investigate why some devices fail updates or end up unstable after rollback.
Separately, Microsoft’s recent Windows 11 servicing and security work included deliberately disabling legacy dial-up modem drivers (e.g., AGRSM64.SYS/AGRSM.SYS, SMSERL64.SYS/SMSERIAL.SYS) due to reported vulnerabilities including CVE-2023-31096 (EoP) and CVE-2025-24052 (stack-based buffer overflow), which can present risk even if the modem hardware is unused—at the cost of breaking connectivity for niche systems relying on those drivers. Microsoft also patched nine bypasses reported by Google Project Zero that could undermine the new Windows Administrator Protection feature by enabling silent admin privilege gains via legacy Windows/UAC behaviors (including a token/Logon Sessions-related technique involving NtQueryInformationToken and DOS device object directory creation), ahead of broader availability beyond Insider builds.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Microsoft said the Windows 11 boot failures were caused by systems left in an improper state after failed December 2025 security update installations and rollbacks. The company also said it was developing a partial mitigation to stop more devices from becoming unbootable during future update attempts.
Recent Windows 11 cumulative updates intentionally decommissioned several legacy modem drivers, including Agere and Motorola soft-modem components, because of serious security vulnerabilities such as CVE-2023-31096 and CVE-2025-24052.
After installing the January 2026 cumulative update KB5074109 on Windows 11 24H2 and 25H2, some affected devices failed to boot and displayed a BSOD with the stop code UNMOUNTABLE_BOOT_VOLUME.
Earlier in January 2026, Microsoft made the new Windows Administrator Protection feature available to users in Windows Insider Canary builds, though it was not yet generally available.
Shortly before Windows Administrator Protection became available to users earlier in January 2026, Microsoft patched multiple flaws, including a DOS device object directory issue involving shadow admin token impersonation.
During the December 2025 update cycle, some Windows 11 devices failed to install the security update and rolled back into an 'improper state.' Microsoft later said this condition set up affected systems for later boot failures.
In December 2025, Google Project Zero researcher James Forshaw reported nine vulnerabilities that could bypass Windows Administrator Protection, largely by exploiting known UAC-related behaviors to silently gain administrator privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcesecurityonline.info
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.