top of page

Microsoft’s Windows 11 Emergency Update Fixes Some Failures, but Leaves AMD and Explorer Bugs Open

Sep 16
13 min read

Microsoft released a Windows 11 emergency update only six days after September’s security patch triggered serious failures across some PCs. The new package repairs Remote Desktop, virtual-machine folder sharing, and one category of USB audio problems. It does not resolve every reported regression.

That distinction matters because the original update combined major security work with several long-requested Windows features. Users received a movable taskbar, a more configurable Start menu, improved Search controls, and a faster File Explorer Home page. Some also encountered broken applications, inaccessible desktops, missing audio, or unstable graphics.

The result is a familiar conflict between Microsoft’s automatic security model and the stability businesses expect from Windows. Removing the September patch can restore affected systems, according to user reports. Doing so also removes security protections, leaving administrators with an uncomfortable choice.

What the Windows 11 Emergency Update Actually Fixes

KB5129195 is a targeted recovery package, not a complete repair for every September update complaint.

Microsoft released KB5129195 on September 14 for Windows 11 versions 25H2 and 24H2. The cumulative, out-of-band update advances those releases to builds 26200.9457 and 26100.9457. An out-of-band update arrives outside Microsoft’s regular monthly schedule when waiting for the next cycle presents unacceptable operational or security risk.

The package follows KB5124008, which arrived through the September 8 Patch Tuesday cycle. Microsoft says the new update downloads and installs automatically through Windows Update. Organizations using managed deployment channels receive it according to their configured policies.

Microsoft’s official update notice identifies three repaired areas. These involve Remote Desktop Services, shared folders used by certain Linux virtual machines, and multichannel operation on some USB audio devices.

The first fix addresses instability in Remote Desktop Services, commonly abbreviated as RDS. Affected systems could reject Remote Desktop Protocol connections, block sign-ins, or remain stuck while configuring a remote session. Servers could also become unresponsive.

The damage extended beyond the connection itself. Microsoft Management Console, RDS Licensing Diagnoser, File Explorer, and the Windows Update settings page could stop responding in affected environments. That made diagnosis harder because administrators could lose access to tools needed to investigate the failure.

The second fix concerns applications running Linux virtual machines through Microsoft’s Host Compute Service. These applications can use Plan9, a file-sharing protocol, to expose Windows folders inside a Linux guest. The September update allowed virtual machines to start while making their shared host folders disappear or become inaccessible.

That failure affected more than conventional development environments. Claude Cowork and some Windows Subsystem for Linux applications rely on this virtualization path for local file access. When the shared folders vanished, the applications could open but could not complete storage-dependent actions.

The third repair covers USB Audio Class 1.0 devices operating in eight-channel or 3D audio modes. Those devices could continue working in standard stereo while failing under their advanced channel configurations. KB5129195 restores those multichannel modes.

Microsoft also included protection for CVE-2026-62721, an elevation-of-privilege vulnerability in the Windows User-Mode Power Service. Elevation of privilege means an attacker with existing access can gain permissions beyond those originally granted.

That security component makes the package more than a conventional compatibility hotfix. Microsoft classifies KB5129195 as a security update for Windows 11 versions 25H2 and 24H2. It is cumulative, so it retains earlier improvements and protections.

The timing shows how quickly the confirmed problems crossed Microsoft’s intervention threshold. Its release health bulletin says the company identified issues after the September 8 update. The corrective package followed on September 14 at 10 a.m. Pacific Time.

However, the bulletin names only confirmed problem categories. It does not say KB5129195 fixes every crash or display failure reported after September 8. That gap defines the central tension around the update.

The September Patch Mixed Welcome Features With Serious Regressions

Microsoft delivered overdue interface improvements inside a security release that some users could not safely treat as routine.

The September package incorporated changes first distributed through the August 27 non-security preview. Its visible additions addressed complaints that had followed Windows 11 since Microsoft redesigned the desktop.

Users can position the taskbar at the top, bottom, left, or right side of the screen. The system preserves tooltips, flyouts, and options such as never combining taskbar icons across those positions. A smaller mode also reduces icon size and taskbar height on compact displays.

The revised Start menu offers small and large layouts. Users can independently show or hide its Pinned, Recommended, and All sections. They can also remove their profile name and picture from the menu.

Windows Search now labels results by source, including applications, settings, files, the web, or Microsoft Store. It can automatically index frequently used folders. That should make local files easier to locate without forcing users to interpret a mixed results list.

File Explorer Home also received performance and touch improvements. Microsoft says it opens faster, responds more quickly, and supports touch scrolling within the Recommended section. These changes target everyday interactions rather than specialized enterprise functions.

Microsoft documented these additions before the security release in its August preview summary. The September package then brought the accumulated changes to a much broader population through the normal security-update channel.

That rollout model helps explain the sharp contrast in user experiences. Preview updates reach people who choose early access, while security updates have far wider distribution. Businesses often deploy them rapidly because delaying fixes creates measurable exposure.

A consumer who wanted a movable taskbar could postpone the feature. An administrator responsible for a remotely accessed fleet had less freedom once the same release carried security protections. The update therefore linked optional interface changes with operationally urgent maintenance.

The emergency response confirms that Microsoft considered several regressions important enough to bypass its normal cadence. It does not establish that the entire September release was broadly defective. Microsoft describes the confirmed failures as affecting some devices and environments.

Scope matters here. Remote Desktop instability can depend on server roles, session configuration, and supporting tools. Plan9 failures require applications that use HCS-managed Linux virtual machines and shared Windows folders. The confirmed multichannel audio problem applies to USB Audio Class 1.0 devices.

These conditions make the failures narrower than a universal Windows outage. They also make pre-release testing difficult because Microsoft must account for enormous combinations of hardware, drivers, virtualization layers, and enterprise policies.

Still, narrow failures can carry outsized consequences. A Remote Desktop problem affects the exact organizations that rely on centralized access and managed sessions. A folder-sharing regression can disable the main function of an application even while that application appears to launch normally.

That is why describing KB5129195 as an emergency update is accurate but incomplete. It is an urgent response to confirmed regressions and additional security work. It is not proof that Microsoft has resolved the broader collection of September complaints.

Microsoft’s Partial Fix Exposes the Security and Stability Tradeoff

The update restores several broken paths while leaving customers dependent on Microsoft’s judgment about which failures are confirmed and urgent.

Windows security updates are designed to be cumulative. Each package carries prior fixes forward, reducing the need to install a long chain of separate patches. That approach simplifies servicing but increases the functional surface contained inside each release.

When a cumulative update causes a regression, uninstalling it is rarely a clean decision. The rollback removes the unwanted change, but it can also remove vulnerability patches and servicing improvements. Administrators must compare an immediate operational failure against less visible security exposure.

KB5129195 narrows that dilemma for organizations affected by Remote Desktop or Plan9 folder sharing. They can install the replacement package and retain the September protections. The package also reaches Windows Update for Business and Windows Server Update Services.

The situation remains harder for users facing problems outside Microsoft’s current fix list. Reports describe AMD Radeon driver timeouts, black screens, missing displays, freezes, and crashes. Other users report File Explorer failures or File History no longer detecting connected backup drives.

Microsoft has not publicly confirmed the AMD graphics and File History reports in the KB5129195 documentation. The company’s published notes also do not list a general fix for Explorer crashes outside the confirmed Remote Desktop scenario.

That omission does not prove Windows is uninvolved. Graphics failures can emerge from interactions among an operating-system update, the display driver, firmware, hardware acceleration, and individual applications. Reproducing the exact failing combination can take time.

It also does not prove every reported AMD failure shares one cause. Independent reports mention several Radeon generations and different symptoms. A black screen, driver timeout, disabled display, and total system freeze can arise from related or separate defects.

Independent testing found that KB5129195 restored Claude Cowork and custom WSL-based applications that had lost access to shared folders. The same testing found no listed repair for AMD graphics, File History, or separate Explorer failures.

The report associates Explorer crashes mainly with enterprise environments using profile-management products such as Citrix UPM, FSLogix, Omnissa Horizon, or ProfileUnity ProfileDisks. Affected users can reach a black screen after signing in because Explorer provides the desktop and taskbar.

Restarting Explorer through Task Manager reportedly restores the shell in some cases. That is a recovery step rather than a durable fix. It also becomes impractical when the problem affects a large pool of managed desktops.

The third-party application failure illustrates another layer of pressure. Anthropic initially had to explain why Claude Cowork could no longer reach files that users had already authorized. Microsoft later confirmed the underlying host-folder-sharing problem and repaired it through KB5129195.

From the user’s perspective, the application stopped working. Responsibility was distributed across an Anthropic product, Microsoft’s virtualization infrastructure, and the Windows servicing layer. Only one company could correct the operating-system regression.

That dependency places application developers in a difficult position. They can test against preview builds, but they cannot reproduce every managed configuration. They can provide error messages and workarounds, but they cannot patch a closed Windows component.

The same logic applies to AMD. A graphics vendor can adjust its driver when an operating-system change exposes a compatibility problem. However, Microsoft must determine whether Windows introduced the failure, revealed a pre-existing driver defect, or merely coincided with unrelated reports.

The Windows 11 emergency update therefore resolves the best-understood failures first. That is sensible incident management. It also leaves some users without an official diagnosis while an automatically delivered security package remains the leading suspected trigger.

AMD GPU Crashes and Explorer Failures Remain Unconfirmed

The most alarming reports are also the least settled, so readers should separate observed symptoms from confirmed causes.

AMD Radeon users have described display-driver timeouts, black screens, vanished displays, and complete freezes after installing the September update. Reports cited by specialist outlets cover products including the RX 6600, RX 7700 XT, RX 7800 XT, RX 7900 GRE, RX 7900 XTX, and RX 9070 XT.

That range suggests the complaints are not obviously confined to one GPU model. It does not establish a single Windows defect across every listed card. Public reports lack the controlled telemetry needed to separate update behavior from driver, firmware, and application variables.

Some users say reverting the Windows update restores stability. Others report that installing an older Radeon driver does not help. Both observations make the operating-system update a plausible suspect, but neither provides a definitive root cause.

The original reported AMD failures also include Explorer hang-ups and broken third-party integrations. The confirmed Plan9 repair explains some integration failures, but it does not cover every reported desktop or graphics problem.

Explorer deserves especially careful treatment because it serves multiple roles. It displays folders, but it also provides the Windows desktop shell, taskbar, and parts of the sign-in experience. An Explorer failure can therefore resemble a full system outage.

Microsoft’s KB documentation confirms that File Explorer can become unresponsive alongside the Remote Desktop problem. That statement applies to affected RDS environments. It should not be stretched into confirmation of every separate Explorer crash reported after September 8.

The distinction changes what users should do. Someone running an affected Remote Desktop environment has an official repair path through KB5129195. Someone experiencing a standalone Explorer crash has evidence that the update may be involved, but no universal Microsoft fix yet.

USB audio has a similarly divided status. KB5129195 restores eight-channel and 3D modes on affected USB Audio Class 1.0 devices. Microsoft separately acknowledges that some devices may still fail to start, produce no output, or show Code 10 in Device Manager.

Volume controls may remain unresponsive or fixed at zero. Sound settings can also fail to open. Microsoft says it is still working on a resolution for those symptoms.

This partial repair demonstrates why an emergency package should not be treated as a clean endpoint. Different symptoms within one hardware category can have distinct causes. Microsoft fixed the multichannel path while leaving the more severe no-output condition open.

Users should also resist treating social reports as prevalence data. Posts can identify reproducible patterns before official documentation catches up. They cannot reliably show what percentage of Windows devices are affected.

Large update populations naturally generate many support complaints, including failures unrelated to the release. The useful signal comes from matching build numbers, hardware models, driver versions, crash signatures, and recovery behavior.

For AMD systems, that means recording the installed Windows build and Radeon driver before changing anything. Users should note whether the failure occurs during gaming, ordinary desktop activity, video playback, or immediately after sign-in.

For Explorer failures, administrators need to identify the profile-management layer and whether restarting Explorer restores the session. They should distinguish an RDS-hosted environment from a physical desktop experiencing an unrelated shell crash.

Businesses should test KB5129195 in a representative deployment ring before broad release. A deployment ring is a controlled group that receives updates earlier than the wider fleet. It provides evidence from the organization’s actual hardware and software combinations.

Organizations should not casually remove a security update across an entire fleet. Any rollback needs a documented risk decision, limited scope, and a plan to reinstall a corrected package. Microsoft’s cumulative update model makes indefinite deferral increasingly difficult.

Consumers facing an unusable machine have fewer diagnostic resources. They can verify the build under Settings, System, and About when the desktop remains accessible. Build 26200.9457 identifies KB5129195 on version 25H2, while build 26100.9457 identifies it on 24H2.

Those build numbers confirm installation, not resolution. An unchanged AMD crash after the update is consistent with Microsoft’s published fix list. The company never claimed this package included an AMD-specific repair.

The Bigger Pressure Falls on Microsoft’s Testing Model

Microsoft must ship security fixes quickly without turning customers and third-party developers into the final compatibility test.

Windows supports an unusually broad hardware and application market. Microsoft must service consumer laptops, gaming desktops, corporate virtual desktops, specialized peripherals, developer environments, and servers through related update infrastructure.

That diversity makes perfect compatibility unrealistic. Yet Microsoft controls the rollout mechanism, the update packaging, and much of the diagnostic telemetry. Customers reasonably expect the company to detect damaging interactions before mandatory deployment.

The September release placed several categories of change into one cumulative package. It carried security protections, servicing improvements, and user-interface features inherited from the preview channel. Each category can touch different parts of the operating system.

The movable taskbar changes the shell. Search and File Explorer updates affect indexing and navigation. Security hardening can alter permissions, services, or component behavior. Virtualization fixes interact with applications that expose Windows files to Linux guests.

Bundling does not prove that any visible feature caused the reported regressions. It does make fault isolation harder for users because the update arrives as one operational unit. Most people cannot selectively retain the security work while removing a suspected component change.

Microsoft’s preview program is intended to surface compatibility problems before broad deployment. Enterprise customers also use staged rollouts to control exposure. September’s emergency update shows that both layers still have blind spots.

Some failures need production scale to become visible. A profile-management interaction may require a particular virtual desktop image, sign-in sequence, and policy set. A Radeon problem may depend on a specific graphics path and driver generation.

However, an out-of-band release six days after Patch Tuesday indicates that Microsoft found actionable evidence quickly. The company confirmed three issue families, prepared fixes, validated them, and distributed a cumulative replacement.

That response is better than leaving customers on workarounds until October. It also raises questions about why the defects survived preview testing. Microsoft has not published a detailed root-cause analysis for the confirmed regressions.

A transparent explanation would help developers understand whether their integrations need defensive changes. It would also help administrators decide which workloads require expanded pre-deployment testing.

The comparison is not Microsoft against AMD or Anthropic as a conventional product contest. The primary conflict is Microsoft’s promise of secure, automatic servicing against the reality of ecosystem compatibility.

Third-party vendors still carry responsibilities. AMD must investigate driver behavior and communicate confirmed findings. Application developers should test preview builds and present meaningful error messages when operating-system services fail.

Yet those vendors cannot control a Windows security update. Microsoft’s platform role gives it both broader visibility and greater responsibility. When the platform breaks an integration, downstream companies absorb support costs before the platform owner delivers a repair.

Users also absorb the uncertainty. They must decide whether a symptom justifies rollback, whether a replacement update addresses their case, and whether online reports describe the same failure.

The Windows 11 emergency update reduces that uncertainty for several confirmed problems. It does not remove it for AMD graphics, independent Explorer crashes, File History, microphones, or USB devices that still produce no sound.

What Windows Users and Administrators Should Watch Next

The next meaningful signals are Microsoft’s issue confirmations, AMD’s driver findings, and evidence that October’s cumulative update closes the remaining gaps.

First, watch Microsoft’s Windows release-health pages for newly confirmed issues. Those pages distinguish active investigations from resolved incidents and associate each problem with affected versions. A formal AMD or standalone Explorer entry would turn user reports into an acknowledged servicing problem.

The wording will matter. Confirmation that some Radeon devices are affected would strengthen the case against the September update. A narrower finding involving one driver branch or hardware configuration would reduce the scope of that conclusion.

Microsoft may also add a Known Issue Rollback, or KIR. This mechanism remotely disables a problematic non-security change while preserving the rest of an update. Its appearance would signal that Microsoft isolated a reversible component change.

Second, watch AMD’s Radeon driver notes and support communications. A hotfix that names the September Windows update would show that AMD found a driver-side mitigation. A joint statement would provide stronger evidence about the interaction and affected hardware.

Driver releases should be judged by documented changes and repeatable testing, not version numbers alone. Users need to know whether the fix addresses timeouts, black screens, missing displays, or complete freezes. Those symptoms should not be treated as interchangeable.

Third, watch Microsoft’s next cumulative release. October’s update should carry the KB5129195 fixes forward because Windows updates are cumulative. It will reveal whether Microsoft also resolves the remaining USB audio condition and acknowledges other September regressions.

The strongest positive signal would be an updated issue list followed by a documented resolution. Falling complaint volume would support that result, especially across consistent builds and hardware. Silence alone would not prove the problems disappeared.

Organizations should use the intervening weeks to improve their own evidence. Preserve event logs, memory dumps, build numbers, driver versions, affected hardware identifiers, and reproduction steps. That information gives Microsoft and vendors something testable.

IT teams should also review deployment rings. A pilot group should represent remote workers, virtual desktops, development machines, AMD systems, and specialized USB hardware. Testing only standard office laptops will miss the combinations highlighted by this incident.

Application developers that depend on WSL, Hyper-V, or shared host folders should add explicit checks for unavailable mounts. A clear storage-access error cannot repair Windows, but it prevents users from mistaking an infrastructure failure for lost data.

Consumers should install KB5129195 because it contains security protections and confirmed repairs. They should also understand its limits. Installing it does not guarantee that an unrelated Explorer, File History, audio, or Radeon problem will disappear.

If a machine remains unstable, document the exact failure before trying multiple fixes. Changing Windows builds, drivers, firmware, and application settings simultaneously destroys useful evidence. A controlled sequence makes the responsible component easier to identify.

Microsoft’s Windows 11 emergency update is therefore a recovery milestone, not the end of the September incident. It fixes Remote Desktop, Plan9 folder sharing, and multichannel USB audio while preserving essential security work.

The unresolved reports now carry the most importance. Will Microsoft formally connect AMD crashes and standalone Explorer failures to KB5124008, or will investigation reveal narrower causes? That answer will determine whether September was a contained compatibility incident or evidence of a broader testing problem.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page