- Confirmed Regression: Microsoft says April’s KB5083769 update may break image-mount operations in legacy versions of Macrium Reflect, along with Acronis, UrBackup Server, and NinjaOne Backup on patched Windows machines; Macrium says Reflect X is not affected.
- Driver Blocklist: The April 14, 2026 update added the psmounterex.sys kernel driver to Microsoft’s Vulnerable Driver Blocklist to close buffer overflow CVE-2023-43896.
- Microsoft Guidance: Microsoft tells customers to update their backup application to a build with the required driver protections rather than uninstall the security patch.
- Diagnostic Signal: Administrators can confirm the cause by checking Event Viewer for Event ID 3077 in the Code Integrity log showing psmounterex.sys was blocked.
- Vendor Builds Pending: Administrators running affected builds should move to vendor versions that no longer rely on the blocklisted psmounterex.sys driver; for Macrium, Reflect X is not experiencing this issue.
[UPDATE 28.05.2026 – 21:57 CEST] This article has been corrected to clarify that the Macrium-related impact concerns legacy versions of Macrium Reflect and that Macrium says its latest release, Reflect X, is not experiencing this issue; references that could have implied all Macrium Reflect versions are affected have been narrowed accordingly.
Microsoft says the April 2026 Windows security update KB5083769 may break image-mount operations in four named backup products on patched Windows machines after blocklisting the psmounterex.sys kernel driver. The Macrium-related impact concerns legacy versions of Macrium Reflect, while Macrium says Reflect X is not affected. Other named applications include Acronis Cyber Protect Cloud, UrBackup Server, and NinjaOne Backup, and the regression sits alongside other April side effects already tracked across enterprise fleets.
April’s cumulative update, released on April 14, 2026 alongside KB5082052, added psmounterex.sys to the Microsoft Vulnerable Driver Blocklist to close a high-severity buffer-overflow flaw. Image-mount and related backup workflows may fail on affected product builds across Windows 10, Windows 11, and Windows Server installations, and Microsoft says customers should update their backup application rather than uninstall or pause the security patch.
“In the April 2026 Windows security update, we added known vulnerable kernel driver psmounterex.sys to the Vulnerable Driver Blocklist. Backup applications that rely on this driver may experience failures when attempting to mount or manage disk images.”
Microsoft
What Microsoft Changed
April’s cumulative update added psmounterex.sys to the Vulnerable Driver Blocklist, Microsoft’s curated list of kernel drivers that Windows refuses to load because attackers can abuse them. Psmounterex.sys carries a high-severity buffer overflow tracked as CVE-2023-43896 that allows local privilege escalation and arbitrary code execution. Closing that flaw matters because attackers increasingly chain signed-but-broken drivers into bring-your-own-vulnerable-driver attacks, loading legitimate but flawed kernel modules to gain ring-zero code execution on otherwise patched machines.
Microsoft enforces the blocklist through App Control for Business policies that ship with Windows 10, Windows 11, and Windows Server, refreshing the list roughly once or twice a year and bundling it into cumulative releases. Psmounterex.sys is a shared mounting driver that several backup vendors or legacy product builds integrated for image-file mount operations, so a single blocklist entry affected multiple products and builds simultaneously.
Microsoft has not advised customers to walk back the block. The underlying privilege-escalation hole is the kind of primitive ransomware operators routinely weaponize, so image-mount failures in affected backup builds are being treated as collateral damage from a security fix that needs to stay in place.
Affected Backup Apps, Builds, and Symptoms
Image creation generally still completes on affected systems; failures appear on image-mount and snapshot operations that rely on psmounterex.sys. KB5083769 and KB5083631 block the psmounterex.sys driver used by affected backup application builds, including legacy Macrium Reflect versions, Acronis, UrBackup, and NinjaOne, when those backup applications attempt image-mount operations through the blocked driver.
Affected jobs may surface as VSS snapshot timeouts, with operators describing errors such as “The backup has failed because Microsoft VSS has timed out during the snapshot creation” or VSS_E_BAD_STATE. Administrators can confirm the source by checking Event Viewer for Event ID 3077 in the Code Integrity log, tied to Policy ID {D2BDA982-CCF6-4344-AC5B-0B44427B6816}, which records that psmounterex.sys was blocked from loading. Such a log entry is the cleanest in-product signal that the blocklist, not the backup software itself, is the source of the failure.
Microsoft’s Guidance and Broader April Issues
Microsoft has advised customers to update their backup application to a build that ships with the required driver protections rather than uninstall or pause the April update, and the guidance to install latest application builds has stayed consistent across follow-up statements. For Macrium users, the issue concerns legacy versions of Reflect; Macrium says Reflect X is not experiencing this issue. An unofficial registry workaround circulating among administrators temporarily disables blocklist enforcement for psmounterex.sys, but it restores the same privilege-escalation exposure the patch was designed to close and is not a path Microsoft endorses.
Backup failures join a same-month cluster of side effects. Windows Server installations may fail or enter restart loops after the April updates, prompting Microsoft to ship out-of-band emergency updates. Some Windows Server 2025 devices may boot into BitLocker recovery after KB5082063 and prompt users for the recovery key, and HP and Dell PCs may experience BitLocker lockouts and boot loops following the April 2026 Windows 11 cycle. The next operational checkpoint for administrators is verifying whether their deployed backup builds still depend on psmounterex.sys and installing vendor releases that remove or replace the blocklisted driver. For Macrium, the company’s latest Reflect X release is not experiencing this issue; the Macrium impact described here concerns legacy Reflect versions.
Last Updated on May 28, 2026 10:11 pm CEST


