Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Microsoft Confirms Windows 11 25H2 UI Features Broken Along With 24H2 Following Update

Posted on December 3, 2025December 3, 2025 By CWS

Microsoft has formally confirmed a vital situation affecting enterprise and managed environments working Home windows 11 variations 24H2 and 25H2.

The bug, first triggered by cumulative updates launched in July 2025, causes widespread failures in important UI elements, rendering the desktop unusable for a lot of customers.

In keeping with an up to date help doc launched on December 2, 2025, the problem stems from a timing failure within the registration of XAML-dependent packages.

When these updates are utilized, the mandatory Extensible Utility Markup Language (XAML) dependencies, particularly packages like MicrosoftWindows.Consumer.CBS fails to register earlier than the Home windows Shell initializes. This race situation successfully breaks the visible layer of the working system earlier than the consumer may even work together with it.​

Home windows 11 25H2 UI Options Damaged

The core of the issue lies within the dependency chain between the Home windows Shell and its underlying AppX packages. Trendy Home windows interface components, such because the Begin Menu and Taskbar, depend on “CBS” (Element Primarily based Servicing) consumer packages to render their UI.​

Microsoft recognized that the next particular dependencies are failing to register in time through the logon sequence:

MicrosoftWindows.Consumer.CBS_cw5n1h2txyewy

Microsoft.UI.Xaml.CBS_8wekyb3d8bbwe

MicrosoftWindows.Consumer.Core_cw5n1h2txyewy

When Explorer.exe or SiHost.exe (the Shell Infrastructure Host) makes an attempt to name these lacking assets, the processes crash or grasp, resulting in a “black display screen” state or a non-functional desktop.​

Whereas private gadgets are largely unaffected, the influence on enterprise environments is important. The difficulty is most prevalent in Digital Desktop Infrastructure (VDI) and different non-persistent OS installations.

In these environments, the place a recent OS occasion is provisioned for each consumer logon, the race situation happens repeatedly as a result of the applying packages have to be reinstalled and registered at each single sign-in occasion.​

Beneath is the breakdown of failure signatures directors could encounter:

Binary ComponentFailure Signature / Person ExperienceExplorer.exeUsers go browsing to a very black display screen; Taskbar fails to render; Explorer crashes instantly upon begin.StartMenuExperienceHostThe Begin menu fails to open or shows a “Crucial Error” message to the end-user.ShellHost.exeThe Shell Infrastructure Host crashes repeatedly, stopping UI initialization.Consent.exeThe Person Account Management (UAC) dimming display screen and immediate fail to seem.SystemSettingsThe Settings app (Begin > Settings) fails to launch silently with no error message.XAML Appsvarious trendy inbox apps crash instantly upon initialization.

Microsoft is at present growing a everlasting decision, however has not supplied a particular timeline for the repair. Within the interim, IT directors should manually intervene to revive performance.

For persistent environments, directors can manually register the lacking packages by way of PowerShell by focusing on the AppxManifest.xml recordsdata within the C:WindowsSystemApps listing.​

For non-persistent VDI environments, the place guide intervention per session is unimaginable, Microsoft recommends a synchronous logon script.

This script acts as a wrapper, forcibly registering the Microsoft.UI.Xaml and Consumer.CBS packages earlier than permitting explorer.exe to launch. This sequence ensures the dependencies are totally provisioned, stopping the race situation that results in the UI failure.​

Comply with us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:24H2, 25H2, Broken, Confirms, Features, Microsoft, Update, Windows

Post navigation

Previous Post: re:Invent 2025: AWS and Security Vendors Unveil New Products and Capabilities 
Next Post: Penn and Phoenix Universities Disclose Data Breach After Oracle Hack

Related Posts

Threat Actors Hijack Popular npm Packages to Steal The Project Maintainers’ npm Tokens Cyber Security News
CISA Warns of Control Web Panel OS Command Injection Vulnerability Exploited in Attacks Cyber Security News
Microsoft Releases Cumulative Update for Windows 10 With July Patch Tuesday 2025 Cyber Security News
Record-breaking 11.5 Tbps UDP Flood DDoS Attack Originated from Google Cloud Platform Cyber Security News
Insecure GitHub Actions in Open Source Projects MITRE and Splunk Exposes Critical Vulnerabilities Cyber Security News
Hackers Exploiting Fake Battlefield 6 Popularity to Deploy Stealers and C2 Agents Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Scanner Tool for Detecting Exposed ReactJS and Next.js RSC Endpoints (CVE-2025-55182)
  • Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hosts
  • Operation DupeHike Attacking Employees Using Weaponized Documents DUPERUNNER Malware
  • Threat Actors Using Malicious VSCode Extension to Deploy Anivia Loader and OctoRAT
  • India’s New SIM-Binding Rule for WhatsApp, Signal, Telegram, and Other Messaging Platforms

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Scanner Tool for Detecting Exposed ReactJS and Next.js RSC Endpoints (CVE-2025-55182)
  • Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hosts
  • Operation DupeHike Attacking Employees Using Weaponized Documents DUPERUNNER Malware
  • Threat Actors Using Malicious VSCode Extension to Deploy Anivia Loader and OctoRAT
  • India’s New SIM-Binding Rule for WhatsApp, Signal, Telegram, and Other Messaging Platforms

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark