Microsoft has released the September 2025 Windows security update to fix problems introduced by the August 2025 patches.
The earlier updates inadvertently caused unexpected User Account Control (UAC) prompts and disrupted application installations for non-administrative users across multiple Windows versions.
CVE-2025-50173 vulnerability and security patchThe issue originated from a patch addressing CVE-2025-50173, a Windows Installer privilege escalation vulnerability. If exploited, attackers could gain SYSTEM privileges, compromising affected systems.
To mitigate this risk, Microsoft introduced new UAC prompts, requiring administrative credentials in more scenarios to prevent unauthorized privilege escalation.
Unintended UAC prompt behaviorThe updated UAC system produced unexpected prompts in routine cases, including:
This disrupted workflows for non-admin users, who encountered frequent and unnecessary requests for admin credentials.
Affected Windows versionsMicrosoft confirmed that the bug impacted a broad list of platforms, including:
The September 2025 update refines UAC handling:
Microsoft introduced new registry keys to give administrators control:
SecureRepairPolicy
SecureRepairWhitelist
These can be added under:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer
The configuration allows trusted MSI files to bypass unnecessary UAC prompts, reducing disruptions in managed environments.
Fix for NDI streaming performance issuesAlongside the UAC changes, Microsoft also addressed a second bug from the August 2025 updates. The flaw caused lag and stuttering in NDI streaming software on Windows 10 and 11 systems.
The fix improves performance and stability for NDI applications widely used in broadcasting and live streaming setups.