Microsoft released KB5082123 on April 14, 2026, a cumulative security update for Windows 10 Version 1809 and Windows Server 2019 that patches five vulnerabilities across core Windows components. The update raises affected systems to OS Build 17763.8644 and addresses two critical remote code execution flaws in Remote Desktop Services and the SMB protocol.
With unauthenticated RCE in RDS and SMB among the fixes, KB5082123 is a high-priority patch for any remaining Windows 1809 and Server 2019 systems — but documented post-install issues mean admins should test before broad deployment.
Key takeaways
- KB5082123 was released April 14, 2026, for Windows 10 Version 1809 and Windows Server 2019.
- It patches five CVEs (CVE-2026-0847 through CVE-2026-0851), including critical RCE in Remote Desktop Services and SMB.
- The update brings systems to OS Build 17763.8644 and requires a restart.
- Known issues affect Print Spooler, Remote Desktop connections and SMB file-sharing performance.
- Admins should pilot-test then deploy promptly given the severity of the SMB and RDS flaws.
Affected
What KB5082123 fixes
Microsoft published KB5082123 on April 14, 2026, as a cumulative security update for Windows 10 Version 1809 and Windows Server 2019. The update patches five vulnerabilities in core Windows components and updates affected systems to OS Build 17763.8644.
The flaws span remote code execution, privilege escalation and a security feature bypass. Two of the fixes address unauthenticated remote code execution, which is typically the highest concern for network-exposed servers.
- CVE-2026-0847 — Windows Kernel elevation of privilege (Critical)
- CVE-2026-0848 — Remote Desktop Services remote code execution (Critical)
- CVE-2026-0849 — Print Spooler elevation of privilege (High)
- CVE-2026-0850 — NTLM authentication security feature bypass (Medium)
- CVE-2026-0851 — SMB remote code execution (Critical)
- OS Build after install: 17763.8644
- Five CVEs patched: CVE-2026-0847 to CVE-2026-0851
Why it matters
According to Microsoft's documentation, the SMB flaw (CVE-2026-0851) and the Remote Desktop Services flaw (CVE-2026-0848) can be exploited by an unauthenticated attacker to run arbitrary code on affected systems. Both service classes are frequently exposed on internal networks and, in poorly segmented environments, from the internet.
The kernel (CVE-2026-0847) and Print Spooler (CVE-2026-0849) flaws are local privilege escalation issues that a foothold attacker could chain to reach SYSTEM. The NTLM issue (CVE-2026-0850) is a security feature bypass that Microsoft says could enable unauthorized network access.
Prioritize network-exposed servers
Because the SMB and RDS flaws are described as unauthenticated RCE, servers running these services should be prioritized for patching.
Affected systems
- Windows 10 Version 1809 for 32-bit systems
- Windows 10 Version 1809 for x64-based systems
- Windows Server 2019 (all editions)
- Windows Server 2019 (Server Core installation)
Build and installation details
After installation, systems report OS Build 17763.8644, verifiable with winver or the Get-HotFix cmdlet. A restart is required to complete the update.
PS C:\> Get-HotFix -Id KB5082123- Approximate package size: 847 MB (x64), 623 MB (32-bit)
- Free disk space needed: approximately 1.2 GB
- Typical install time: 15–30 minutes, restart required
The update is distributed via Windows Update, the Microsoft Update Catalog for offline installs, and enterprise channels including WSUS, Configuration Manager (SCCM) and Microsoft Intune.
Known issues
Microsoft's documentation lists several post-install issues that admins should account for before broad rollout:
- Print Spooler service failures or crashes, particularly with legacy printer drivers. Workaround: update printer drivers or temporarily disable the spooler where printing is not required.
- Remote Desktop connection problems, including authentication errors or timeouts. Workaround: clear the RDP credential cache and re-establish connections, or restart Remote Desktop Services.
- Reduced SMB file-sharing performance, especially on large transfers. Workaround: monitor and adjust SMB protocol settings if degradation is significant.
Pilot before production
Microsoft recommends testing in a non-production environment first, especially on systems running legacy or custom applications.
Deployment guidance
- Deploy to a pilot group to catch compatibility issues, especially with legacy printer drivers and custom apps.
- Roll out in phases to limit business impact and monitor system and application health.
- Schedule maintenance windows for critical infrastructure and legacy application hosts before applying the update.
Timeline
Impact & actions
KB5082123 closes five vulnerabilities on legacy Windows systems, two of which are critical unauthenticated RCE, but introduces documented Print Spooler, Remote Desktop and SMB issues.
Security: Addresses unauthenticated remote code execution (RDS, SMB), local privilege escalation to SYSTEM (kernel, Print Spooler) and an NTLM authentication bypass.
Recommended actions · High urgency
- 1Pilot-test KB5082123, then deploy promptly given the critical SMB and RDS flaws
- 2Prioritize servers exposed to SMB or Remote Desktop Services
- 3Update printer drivers before deployment to reduce Print Spooler issues
- 4Verify OS Build 17763.8644 after install with winver or Get-HotFix
Technical details
- CVEs
- CVE-2026-0847, CVE-2026-0848, CVE-2026-0849, CVE-2026-0850, CVE-2026-0851
- Attack vector
- Network (RDS, SMB unauthenticated RCE) and local (kernel, Print Spooler privilege escalation)
- Affected versions
- Windows 10 Version 1809 (32-bit and x64), Windows Server 2019 (all editions, including Server Core)
- Patched versions
- OS Build 17763.8644
Mitigations
- Install KB5082123 via Windows Update, Microsoft Update Catalog, WSUS, SCCM or Intune
- Restrict exposure of SMB and Remote Desktop Services to untrusted networks
Response
Customer guidance
Microsoft advises installing the update promptly, testing in non-production first, and updating printer drivers to the latest versions to mitigate known Print Spooler issues.
FAQ
What does KB5082123 resolve?
KB5082123 resolves five vulnerabilities in Windows 10 Version 1809 and Windows Server 2019, including remote code execution in Remote Desktop Services (CVE-2026-0848) and SMB (CVE-2026-0851), privilege escalation in the Windows Kernel (CVE-2026-0847) and Print Spooler (CVE-2026-0849), and an NTLM authentication bypass (CVE-2026-0850).
Which systems require KB5082123?
The update applies to Windows 10 Version 1809 (32-bit and x64) and Windows Server 2019, including Server Core installations.
What build does KB5082123 install?
After installation, affected systems report OS Build 17763.8644, which you can confirm with winver or Get-HotFix -Id KB5082123. A restart is required.
Are there known issues with KB5082123?
Yes. Documented issues include Print Spooler service failures (especially with legacy drivers), Remote Desktop connection problems, and reduced SMB file-sharing performance. Microsoft recommends testing in non-production first and updating printer drivers.
The bottom line
KB5082123, released April 14, 2026, patches five vulnerabilities in Windows 10 Version 1809 and Windows Server 2019 — including critical RDS and SMB remote code execution — and updates systems to OS Build 17763.8644.
What happens next
What to do






