Microsoft: Windows Server 2025 changes causing app crashes
Microsoft has warned that changes in Windows Server 2025's memory management may cause application crashes for programs using Address Windowing Extensions (AWE). This issue notably affects SQL Server when the Lock Pages in Memory (LPIM) policy is enabled, leading to memory corruption, access violations, and unexpected service terminations. A temporary workaround involves disabling LPIM for the SQL Server service account, though this may impact performance. Microsoft is working on a permanent fix to be delivered in a future update.
AI Analysis
Technical Summary
Windows Server 2025 introduced memory management changes that affect applications relying on Address Windowing Extensions (AWE), which allow use of more than 4GB physical memory in a 32-bit virtual address space. Applications such as SQL Server using LPIM policy experience access violations (0xC0000005), memory corruption, and crashes. The issue manifests as database maintenance failures, crash dumps, and service restarts. Microsoft has acknowledged the problem and provided a temporary workaround by disabling LPIM for the SQL Server service account. A permanent fix is pending in a future Windows update.
Potential Impact
Applications using AWE, especially SQL Server with LPIM enabled, may experience crashes, memory corruption, and service interruptions on Windows Server 2025. This can disrupt database operations and cause unexpected downtime. The performance of SQL Server may degrade if the LPIM policy is disabled as a workaround.
Mitigation Recommendations
Microsoft recommends disabling the Lock Pages in Memory (LPIM) policy for the SQL Server service account as a temporary workaround, understanding that this may affect performance. For other affected applications, disabling AWE usage is advised if possible. Microsoft is actively working on a permanent fix to be released in a future Windows update. Administrators should monitor official Microsoft communications for updates and apply the fix once available.
Microsoft: Windows Server 2025 changes causing app crashes
Description
Microsoft has warned that changes in Windows Server 2025's memory management may cause application crashes for programs using Address Windowing Extensions (AWE). This issue notably affects SQL Server when the Lock Pages in Memory (LPIM) policy is enabled, leading to memory corruption, access violations, and unexpected service terminations. A temporary workaround involves disabling LPIM for the SQL Server service account, though this may impact performance. Microsoft is working on a permanent fix to be delivered in a future update.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Windows Server 2025 introduced memory management changes that affect applications relying on Address Windowing Extensions (AWE), which allow use of more than 4GB physical memory in a 32-bit virtual address space. Applications such as SQL Server using LPIM policy experience access violations (0xC0000005), memory corruption, and crashes. The issue manifests as database maintenance failures, crash dumps, and service restarts. Microsoft has acknowledged the problem and provided a temporary workaround by disabling LPIM for the SQL Server service account. A permanent fix is pending in a future Windows update.
Potential Impact
Applications using AWE, especially SQL Server with LPIM enabled, may experience crashes, memory corruption, and service interruptions on Windows Server 2025. This can disrupt database operations and cause unexpected downtime. The performance of SQL Server may degrade if the LPIM policy is disabled as a workaround.
Defensive Guidance
Microsoft recommends disabling the Lock Pages in Memory (LPIM) policy for the SQL Server service account as a temporary workaround, understanding that this may affect performance. For other affected applications, disabling AWE usage is advised if possible. Microsoft is actively working on a permanent fix to be released in a future Windows update. Administrators should monitor official Microsoft communications for updates and apply the fix once available.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-server-2025-changes-may-cause-app-crashes/","fetched":true,"fetchedAt":"2026-09-08T12:07:14.706Z","wordCount":648}
Threat ID: 6a9ffa72acd9273b499dc857
Added to database: 09/08/2026, 12:07:14 UTC
Last enriched: 09/08/2026, 12:07:36 UTC
Last updated: 09/08/2026, 12:07:36 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.