Microsoft releases Windows 10 builds 16299.371, 15063.1029 - here's what's new

Today is the second Tuesday of the month, which means that it"s Patch Tuesday, the day that Microsoft releases new updates for all supported versions of Windows. This month, every version of Windows 10 for PCs got cumulative updates, and even supported versions of Windows 10 Mobile got updates as well.

Of course, it"s not uncommon for Windows 10 Mobile to be updated in parallel with PCs, but that hasn"t been the case over the last couple of months.

PCs on the Windows 10 Fall Creators Update, or version 1709, will receive KB4093112, which brings the version number to 16299.371 and can be manually downloaded here. Here"s what got fixed:

  • Provides support to control usage of Indirect Branch Prediction Barrier (IBPB) within some AMD processors (CPUs) for mitigating CVE-2017-5715, Spectre Variant 2 when switching from user context to kernel context (See AMD Architecture Guidelines around Indirect Branch Control and AMD Security Updates for more details). Follow instructions outlined in KB4073119 for Windows Client (IT Pro) guidance to enable usage of IBPB within some AMD processors (CPUs) for mitigating Spectre Variant 2 when switching from user context to kernel context.

  • Addresses an issue that causes an access violation in Internet Explorer when it runs on the Microsoft Application Virtualization platform.

  • Addresses an issue in Enterprise Mode related to redirects in Internet Explorer and Microsoft Edge.

  • Addresses an issue that generates an access violation on certain pages in Internet Explorer when it renders SVGs under a high load.

  • Addresses additional issues with updated time zone information.

  • Addresses an issue that might cause the App-V service to stop working on an RDS server that hosts many users.

  • Addresses an issue where user accounts are locked when applications are moved to a shared platform using App-V (e.g., XenApp 7.15+ with Windows Server 2016, where Kerberos authentication isn"t available).

  • Addresses an issue with printing content generated by ActiveX in Internet Explorer.

  • Addresses an issue that causes document.execCommand("copy") to always return False in Internet Explorer.

  • Addresses an issue that, in some instances, prevents Internet Explorer from identifying custom controls.

  • Security updates to Internet Explorer, Microsoft Edge, Windows kpp platform and frameworks, Microsoft scripting engine, Windows graphics, Windows Server, Windows kernel, Windows datacenter networking, Windows wireless networking, Windows virtualization and Kernel, and Windows Hyper-V.

There"s also one known issue to be aware of:

Symptom Workaround
Windows Update History reports that KB4054517 failed to install because of error 0x80070643.

Even though the update was successfully installed, Windows Update incorrectly reports that the update failed to install. To verify the installation, select Check for Updates to confirm that there are no additional updates available.

You can also type About your PC in the search box on your taskbar to confirm that your device is using the expected OS build.

Microsoft is working on a resolution and will provide an update in an upcoming release.


Windows 10 Mobile devices never actually got an update to Redstone 3, so they"re not on build 16299. Instead, they"ll be getting the latest feature2 cumulative update, which is build 15254.369, and that includes the same fixes and improvements as today"s update for version 1703.

And speaking of Windows 10 version 1703, which is also known as the Creators Update, PC and phone users will get KB4093107, or build 15063.1029. It can be manually downloaded here for PCs, and it contains the following fixes:

  • Addresses an issue that generates an access violation on certain pages in Internet Explorer when it renders SVGs under a high load.

  • Addresses an issue with printing content generated by ActiveX in Internet Explorer.

  • Addresses additional issues with updated time zone information.

  • Addresses an issue that might cause the App-V service to stop working on an RDS server that hosts many users.

  • Addresses an issue where user accounts are locked when applications are moved to a shared platform using App-V (e.g., XenApp 7.15+ with Windows Server 2016, where Kerberos authentication isn"t available).

  • Addresses an issue that, in some instances, prevents Internet Explorer from identifying custom controls.

  • Security updates to Internet Explorer, Microsoft Edge, Windows app platform and frameworks, Microsoft scripting engine, Windows graphics, Windows Server, Windows kernel, Windows datacenter networking, Windows wireless networking, Windows Hyper-V, and Windows virtualization and kernel.

There are no known issues with this update, or any of the other updates listed below.

PCs and phones on the Windows 10 Anniversary Update, or version 1607, will see KB4093119, and that brings the build number to 14393.2189. You can manually download it here, and contains the following fixes and improvements:

  • Addresses an issue that generates an access violation on certain pages in Internet Explorer when it renders SVGs under a high load.

  • Addresses an issue with printing content generated by ActiveX in Internet Explorer.

  • Addresses additional issues with updated time zone information.

  • Addresses an issue where user accounts are locked when applications are moved to a shared platform using App-V (e.g., XenApp 7.15+ with Windows Server 2016, where Kerberos authentication isn"t available).

  • Addresses an issue that might cause the App-V service to stop working on an RDS server that hosts many users.

  • Addresses an issue that, in some instances, prevents Internet Explorer from identifying custom controls.

  • Security updates to Internet Explorer, Windows app platform and frameworks, Microsoft scripting engine, Microsoft Edge, Windows graphics, Windows Server, Windows wireless networking, Windows Hyper-V, Windows kernel, and Windows virtualization and kernel.

If your PC is somehow still on Windows 10 version 1511, you"ll see KB4093109, and the build number will be 10586.1540. This update is not available for phones, as Windows 10 Mobile version 1511 is unsupported. You can manually download the update here, and it contains the following fixes:

  • Addresses additional issues with updated time zone information.

  • Addresses an issue that, in some instances, prevents Internet Explorer from identifying custom controls.

  • Security updates to Internet Explorer, Microsoft scripting engine, Windows RDP, Windows kernel, Windows IIS, Windows datacenter networking, Microsoft scripting engine, Microsoft Edge, Windows Hyper-V , and Windows virtualization and kernel.

While the changelog for the 1511 update was modest, PCs still on the original version of Windows 10 got a longer list of changes. Those devices will see KB4093111, which brings the build number to 10240.17831, and can be manually downloaded here. Here"s what"s fixed:

  • Addresses an issue that generates an access violation on certain pages in Internet Explorer when it renders SVGs under a high load.
  • Addresses an issue with printing content generated by ActiveX in Internet Explorer.
  • Addresses additional issues with updated time zone information.
  • Addresses an issue where AppLocker publisher rules that are applied to MSI files don’t match the files correctly.
  • Addresses an issue that prevents the system from booting when you enable LSA (lsass.exe) to run as a protected process by setting the “RunAsPPL” registry entry. Additionally, the Automatic Repair screen may appear.
  • Addresses an issue that blocks failed NTLM authentications instead of only logging them when using an authentication policy with Audit mode turned on. Netlogon.log may show the following:

    SamLogon: Transitive Network logon of <domain>\<user> from <machine2> (via <machine1>) Entered
    NlpVerifyAllowedToAuthenticate: AuthzAccessCheck failed for A2ATo 0x5. This can be due to the lack of claims and compound support in NTLM
    SamLogon: Transitive Network logon of <domain>\<user> from <machine2> (via <machine1>) Returns 0xC0000413

  • Addresses an issue that generates a certificate validation error (0x800B0109 (CERT_E_UNTRUSTEDROOT)) from http.sys.

  • Addresses an issue that prevents PIV smart cards from being recognized.

  • Addresses an issue that, in some instances, prevents Internet Explorer from identifying custom controls.

  • Security updates to Internet Explorer, Windows app platform and frameworks, Microsoft scripting engine, Windows kernel, Windows graphics, Windows Server, Windows datacenter networking, Windows wireless hetworking, and Windows Hyper-V.

Obviously, you shouldn"t need to manually install any of these updates, unless you"re actively trying to block your machine from installing a newer version of Windows 10. You should be able to go to Settings -> Update & security -> Windows Update -> Check for updates, and the service will download the cumulative update that"s appropriate for your machine.

Report a problem with article
Next Article

Samsung updates its Gear IconX wireless earbuds with new audio features

Previous Article

LG reveals that its G7 ThinQ will be unveiled on May 2