Windows 11 24H2/25H2 Update Blocks Mouse and Keyboard in Recovery Mode
## Update Impact on Windows Recovery Environment
Update Impact on Windows Recovery Environment
Microsoft released a security update on Fri, Oct 14, 2025, identified as KB5066835 for OS Build 26100.6899. This update affects Windows 11 versions 24H2 and 25H2, along with Windows Server 2025. A significant issue has been identified with USB keyboards and mice becoming inoperable within the Windows Recovery Environment (WinRE).
This issue arises specifically in WinRE, a critical boot mode used for repairing boot failures, resetting PCs, or restoring from backups. USB input devices continue to function normally during standard Windows sessions but do not respond in this environment. The problem was confirmed by Microsoft on Mon, Oct 17, 2025.
The update also causes additional technical issues, including:
Localhost connections refusing to establish, affecting local development and testing workflows. Installation failures accompanied by unclear error messages. File Explorer's preview pane displaying blank or unresponsive previews.
Microsoft released a security update on Fri, Oct 14, 2025, identified as KB5066835 for OS Build 26100.6899.
Users report sluggish performance, delayed application launches, and erratic multitasking across various devices, from consumer laptops to enterprise servers.
The WinRE disruption poses significant risks during outage responses for IT administrators, potentially escalating minor issues into significant downtime.
Microsoft is actively working on resolving these issues, with fixes expected soon. In the meantime, users are advised to avoid using WinRE when possible and consider alternative recovery methods, such as booting from installation media with functioning peripherals.
For those already affected, uninstalling KB5066835 via Settings > Update & Security > View update history offers temporary relief but may expose systems to security vulnerabilities.
Users are encouraged to monitor official channels for updates to restore full functionality.
Based on reporting by Cyber Security News.
