STIGQter STIGQter: STIG Summary: Microsoft Windows Server 2025 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

Windows Server 2025 must install security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs).

DISA Rule

SV-277982r1181944_rule

Vulnerability Number

V-277982

Group Title

SRG-OS-000439-GPOS-00195

Rule Version

WN25-00-000001

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the operating system to use a patch management system to ensure security-relevant updates are installed within the time period directed by the authoritative source.

Check Contents

Review the operating system documentation and configuration to determine if the system checks in with a patch management system to install security-relevant software updates within a timeframe directed by an authoritative source.

If the operating system does not install security-relevant patches within the time period directed by the authoritative source, this is a finding.

Vulnerability Number

V-277982

Documentable

False

Rule Version

WN25-00-000001

Severity Override Guidance

Review the operating system documentation and configuration to determine if the system checks in with a patch management system to install security-relevant software updates within a timeframe directed by an authoritative source.

If the operating system does not install security-relevant patches within the time period directed by the authoritative source, this is a finding.

Check Content Reference

M

Target Key

5719