The March 2024 Home windows Server updates are inflicting some area controllers to crash and restart, in line with widespread studies from Home windows directors.
Affected servers are freezing and rebooting due to a Native Safety Authority Subsystem Service (LSASS) course of reminiscence leak launched with the March 2024 cumulative updates for Home windows Server 2016 and Home windows Server 2022.
LSASS is a Home windows service that enforces safety insurance policies and handles consumer logins, entry token creation, and password modifications.
As many admins have warned, after putting in the KB5035855 and KB5035857 Home windows Server updates launched this Patch Tuesday, area controllers with the most recent updates would crash and reboot as a consequence of growing LSASS reminiscence utilization.
“Since set up of the march updates (Change in addition to common Home windows Server updates) most of our DCs present consistently growing lsass reminiscence utilization (till they die),” one admin said.
“We have had points with lsass.exe on area controllers (2016 core, 2022 with DE and 2022 core area controllers) leaking reminiscence as effectively. To the purpose all area controllers crashed over the weekend and prompted an outage,” one other one added.
“Our signs had been ballooning reminiscence utilization on the lsass.exe course of after putting in KB5035855 (Server 2016) and KB5035857 (Server 2022) to the purpose that every one bodily and digital reminiscence was consumed and the machine hung,” one admin instructed BleepingComputer.
“The Help rep says they anticipate official comms to be introduced from Microsoft quickly.”
Short-term workaround obtainable
Till Microsoft formally acknowledges this reminiscence leak problem, admins are suggested to uninstall the buggy Home windows Server updates from their area controllers.
“Microsoft Help has really useful that we uninstall the replace in the meanwhile,” the identical admin instructed BleepingComputer.
To take away the troublesome updates, open an elevated command immediate by clicking the Begin menu, typing ‘cmd,’ right-clicking the Command Immediate utility, after which selecting ‘Run as Administrator.’
Subsequent, run one of many following instructions, relying on what replace you will have put in in your Home windows area controller:
wusa /uninstall /kb:5035855
wusa /uninstall /kb:5035857
As soon as uninstalled, you also needs to use the ‘Show or Hide Updates’ troubleshooter to cover the buggy replace so it is going to not seem within the obtainable updates listing.
Microsoft addressed another LSASS memory leak affecting area controllers in December 2022, when affected servers would freeze and restart after putting in Home windows Server updates launched throughout the November 2022 Patch Tuesday.
In March 2022, Microsoft fixed one more LSASS crash, inflicting surprising Home windows Server area controller reboots.
A Microsoft spokesperson couldn’t instantly present extra particulars when contacted by BleepingComputer earlier at this time.