Full Report
Microsoft has released the optional KB5055612 preview cumulative update for Windows 10 22H2 with two changes, including a fix for a GPU paravirtualization bug in Windows Subsystem for Linux 2 (WSL2). [...]
Analysis Summary
# Vulnerability: GPU Paravirtualization Check Failure in WSL2 / Driver Blocklist Update
## CVE Details
- CVE ID: Not specified in the provided text (This is a patch bulletin, not a specific vulnerability disclosure)
- CVSS Score: N/A
- CWE: N/A (Focus is on functional bug fixes and general security hardening)
## Affected Systems
- Products: Windows 10 (specifically version 22H2)
- Versions: Prior to installing KB5055612 (Build 19045.5796)
- Configurations: Systems utilizing GPU paravirtualization within WSL2. Systems hosting the Citrix Session Recording Agent (SRA) version 2411.
## Vulnerability Description
The update addresses two main points:
1. **GPU Bug Fix:** A previously existing issue where the check for GPU paravirtualization (.i.e., related to GPU drivers/hardware integration) was case-sensitive, potentially causing GPU paravirtualization support within WSL2 to fail.
2. **Driver Blocklist Update:** Updates the Windows Kernel Vulnerable Driver Blocklist (`DriverSiPolicy.p7b`) to include additional drivers used in Bring Your Own Vulnerable Driver (BYOVD) attacks.
## Exploitation
- Status: Not explicitly stated if the fixed GPU bug was exploited, but the driver blocklist update implies mitigation against known BYOVD attack techniques.
- Complexity: N/A
- Attack Vector: N/A
## Impact
- Confidentiality: Unknown for the GPU bug, but the driver blocklist targets potential compromise avenues.
- Integrity: Potential instability or failure of GPU acceleration in WSL2 due to the bug. Kernel driver blocks target system integrity violations.
- Availability: Potential instability in WSL2 GPU functions.
## Remediation
### Patches
- **KB5055612 cumulative update preview:** Updates Windows 10 22H2 to build **19045.5796**. Users can download this from the Microsoft Update Catalog.
### Workarounds
If the Citrix Session Recording Agent (SRA) version 2411 is installed, the KB5055612 update may fail or revert:
1. Stop the Session Recording Monitoring service.
2. Install the Microsoft security update (KB5055612).
3. Re-enable the Session Recording Monitoring service.
Note: Error Event 7023 regarding `SgrmBroker.exe` in EventViewer should be ignored, as this component is currently non-functional, and this error will be fixed in future updates.
## Detection
- **Known Issue Indicator:** Event 7023 error regarding `SgrmBroker.exe` (which should be ignored).
- **Detection Methods and Tools:** Applying the update itself serves as the primary detection/resolution method. Monitoring driver policies post-update for blocklist configuration changes.
## References
- Microsoft Update Catalog (Search for KB5055612)
- Citrix support bulletin: hxxps://support.citrix.com/s/article/CTX692505-microsofts-january-security-update-failsreverts-on-a-machine-with-2411-session-recording-agent?language=en_US
- KB5055612 support bulletin: hxxps://support.microsoft.com/en-us/topic/april-22-2025-kb5055612-os-build-19045-5796-preview-428955dc-5f14-4dd8-a828-a1a3d316cb79