Microsoft released KB5087537 on May 12, 2026, the May Patch Tuesday security update for Windows 10 Version 1607 and Windows Server 2016. The update patches vulnerabilities across five Windows components: the kernel, Remote Desktop Services, Windows Graphics (GDI), Microsoft Message Queuing, and the Print Spooler.
Windows 10 1607 and Server 2016 are legacy platforms past mainstream support but still widely deployed. The RDP RCE combined with kernel escalation provides a full remote compromise chain, making this update critical for any organization that hasn't yet migrated.
Key takeaways
- Kernel privilege escalation fixes close multiple paths from standard user to SYSTEM.
- RDP RCE allows remote code execution via crafted requests without user interaction.
- MSMQ RCE enables code execution through malicious queue messages.
- GDI memory corruption exploitable via malformed graphics files.
- Covers Windows 10 1607 (32-bit/x64) and Server 2016 (all editions). Build 14393.9140.
Affected
KB5087537 Patches Kernel, RDP, MSMQ, and Print Spooler Flaws in Windows 10 1607 and Server 2016
Microsoft released KB5087537 on May 12, 2026, the May Patch Tuesday security update for Windows 10 Version 1607 and Windows Server 2016. The update brings both platforms to Build 14393.9140 and patches vulnerabilities across five core Windows components: kernel, Remote Desktop Services, graphics (GDI), Microsoft Message Queuing (MSMQ), and the Print Spooler.
The kernel fixes address multiple privilege escalation paths from standard user to SYSTEM through memory management flaws. The RDP vulnerabilities enable remote code execution via crafted RDP requests without user interaction. The MSMQ flaws allow RCE through malicious queue messages. The GDI issues can be exploited via malformed graphics files. The Print Spooler patches close both escalation and RCE vectors through driver validation weaknesses.
RDP RCE and Kernel Escalation on Legacy Platforms
Windows 10 1607 and Server 2016 are legacy platforms still widely deployed in enterprises. The RDP RCE is the highest-risk flaw: remote, no user interaction required, and RDP is commonly exposed. Combined with kernel escalation, an attacker can achieve full remote compromise.
The MSMQ RCE affects organizations using message queuing for application integration, a pattern common in financial services and manufacturing. The Print Spooler continues to be a persistent attack surface, with new escalation and RCE vectors in every patch cycle. Server 2016 domain controllers and file servers are the most critical targets.
Affected Systems and Known Issues
Windows 10 Version 1607 (32-bit and x64) and Windows Server 2016 (including Server Core). Build updates to 14393.9140. File size approximately 1.2 GB (x64) or 950 MB (x86). Restart required. Available via Windows Update, WSUS, SCCM, and Microsoft Update Catalog.
Known issues
Installation may fail with less than 2 GB free disk space. Temporary performance impact on first boot after installation. Some third-party drivers may need updates for compatibility with the security enhancements.
Timeline
Impact & actions
Five vulnerability categories across kernel, RDP, graphics, MSMQ, and Print Spooler in Windows 10 1607 and Server 2016.
Security: RDP RCE enables remote code execution via crafted RDP requests. Kernel escalation grants SYSTEM from standard user. MSMQ RCE allows code execution through malicious queue messages.
Recommended actions · High urgency
- 1Install KB5087537 on all Windows 10 1607 and Server 2016 systems.
- 2Verify Build 14393.9140 after restart.
- 3Restrict RDP access to trusted networks or VPN only.
- 4Disable MSMQ and Print Spooler on servers where not needed.
Technical details
- Attack vector
- Network (RDP, MSMQ), Local (Kernel, Print Spooler, GDI)
- Affected versions
- Windows 10 1607 / Server 2016 (all builds before 14393.9140)
- Patched versions
- Windows 10 1607 / Server 2016 Build 14393.9140
Mitigations
- Install KB5087537 immediately.
- Restrict RDP exposure via firewall or VPN.
- Disable MSMQ on servers that don't use message queuing.
- Disable Print Spooler on servers that don't need printing.
Response
Vendor
FAQ
What does KB5087537 fix?
Kernel privilege escalation, RDP remote code execution, Windows Graphics (GDI) memory corruption, MSMQ remote code execution, and Print Spooler privilege escalation and RCE vulnerabilities. Updates Build to 14393.9140.
Which systems need KB5087537?
Windows 10 Version 1607 (32-bit and x64) and Windows Server 2016 (Standard, Datacenter, Server Core). All editions on both platforms.
Are there known issues?
Known issues: installation failure with less than 2 GB free disk space, temporary performance impact on first boot, and possible third-party driver compatibility issues.
Does KB5087537 require a restart?
Yes. File size is approximately 1.2 GB (x64) or 950 MB (x86). A restart is required. Plan installation during a maintenance window.
The bottom line
KB5087537 patches kernel privilege escalation, RDP remote code execution, GDI memory corruption, MSMQ RCE, and Print Spooler vulnerabilities in Windows 10 1607 and Server 2016, updating to Build 14393.9140.
What happens next
What to do






