The security update KB5001337 is now generally available for Windows 10 v1909 users. Here the links to download KB5001337 offline installer.
Along with the KB5001330 update released for Windows 10 v20H2 and v2004, Microsoft also released the same security update for Windows 10 v1909 users. Being a security update, it should be automatically installed provided that you did not pause the Windows update. Also, the KB5001337 update does not contain any general fixes or improvements. However, while installing the KB5001337 update, it might automatically download other cumulative updates, if they are needed.
The main security fixes include the patching of Active Directory, RemoteFX vGPU feature, and potential privilege escalation. Other than these major vulnerabilities, this update also improves the security of several Windows components like the fundamentals, kernel, cryptography, virtualization, Windows media, AI platform, etc.
To install the update on an offline machine or if the Windows update is causing problems, download the KB5001337 offline installer using the links given below. After downloading, double-click on the installer and follow the wizard to install the KB5001337 update.
Download KB5001337 offline installer
Use the links below to download KB5001337 offline installer from the Microsoft catalog website.
KB5001337 x86 (32-bit) offline installer (download size: 323.7 MB)
KB5001337 x64 (64-bit) offline installer (download size: 560.7 MB)
If you want KB5001337 download links for Windows Server, ARM64 based systems, or some other version then go to the Microsoft update catalog website to find the appropriate links. All you have to do is click on the Download button next to the appropriate version.
Addresses an issue in which a principal in a trusted MIT realm fails to obtain a Kerberos service ticket from Active Directory domain controllers (DC). This occurs on devices that installed Windows Updates that contain CVE-2020-17049 protections and configured PerfromTicketSignature to 1 or higher. These updates were released between November 10, 2020 and December 8, 2020. Ticket acquisition also fails with the error, “KRB_GENERIC_ERROR”, if callers submit a PAC-less Ticket Granting Ticket (TGT) as an evidence ticket without providing the USER_NO_AUTH_DATA_REQUIRED flag.
Addresses an issue with security vulnerabilities identified by a security researcher. Because of these security vulnerabilities, this and all future Windows updates will no longer contain the RemoteFX vGPU feature. For more information about the vulnerability and its removal, see CVE-2020-1036 and KB4570006. Secure vGPU alternatives are available using Discrete Device Assignment (DDA) in Windows Server LTSC releases (Windows Server 2016 and Windows Server 2019) and Windows Server SAC releases (Windows Server, version 1803 and later versions).
Addresses a potential elevation of privilege vulnerability in the way Azure Active Directory web sign-in allows arbitrary browsing from the third-party endpoints used for federated authentication. For more information, see CVE-2021-27092 and Policy CSP – Authentication.
Security updates to Windows App Platform and Frameworks, Windows Apps, Windows Input and Composition, Windows Office Media, Windows Fundamentals, Windows Cryptography, the Windows AI Platform, Windows Hybrid Cloud Networking, the Windows Kernel, Windows Virtualization, and Windows Media.
That is it.