BlackTree Security · Infrastructure · Automation · AI

The Windows Fix That Restored Remote Desktop Still Leaves Some Citrix Users Staring at a Black Screen

Microsoft’s out-of-band Windows updates fixed the September failure that could make Remote Desktop Services stop accepting connections. They did not end every Citrix black screen problem associated with the same update cycle.

Citrix now warns that some Citrix Virtual Apps and Desktops environments can still present users with a black screen after sign-in, even after the Remote Desktop repair has been installed. Microsoft separately lists an in-progress FSLogix problem in which explorer.exe crashes while the Windows shell is starting.

The distinction matters. One incident prevents a session from being established because Remote Desktop Services becomes unstable. The other can allow sign-in to progress and then fail while loading the user’s desktop. Applying the fix for the first problem does not prove that the second one has been resolved.

Two failures arrived in the same update cycle

BlackTree reported earlier in September that the month’s Windows security updates could leave Remote Desktop users stuck at Connecting, make sign-ins fail and leave servers hanging while waiting for Remote Desktop configuration.

Microsoft has since resolved that RDS problem with cumulative out-of-band updates released on 14 September. Citrix lists updates for supported Windows client and server releases from Windows Server 2012 through Server 2025, alongside Windows 10 and Windows 11.

The remaining black-screen problem is different. Microsoft says it began with the August non-security preview update for Windows 11 and continued into later updates, including September’s security release. Reports have primarily involved virtual-desktop hosts using FSLogix, with the problem appearing more frequently for some existing user profiles.

Microsoft lists the following symptoms:

  • A black screen appears after sign-in and the desktop does not load automatically.
  • The user cannot reach the desktop until the Windows shell is started manually.
  • Application logs may show explorer.exe crashes.

Citrix says Desktop OS Virtual Delivery Agents can exhibit the black screen after installing KB5124008 or its preview predecessor KB5120998. It adds that environments combining Citrix Virtual Apps and Desktops with Citrix Profile Management or FSLogix can remain affected after the RDS out-of-band updates are installed.

The RDS repair is still necessary

Administrators should not read the remaining black-screen warning as a reason to skip the out-of-band Windows updates. They address a separate and serious service failure.

Citrix identifies three useful signatures for the resolved RDS condition:

  • TerminalServices-RemoteConnectionManager event 20498, reporting that Remote Desktop Services took too long to complete a client connection.
  • Winlogon event 6005, reporting that the SessionEnv notification subscriber took too long to process a disconnect.
  • The TermService service remaining in StopPending instead of Running.

Microsoft says the failure could also make management tools, File Explorer and the Windows Update interface become unresponsive. The affected range was unusually broad, covering supported Windows 10 and Windows 11 releases as well as Windows Server 2012 through Windows Server 2025.

The out-of-band updates are cumulative and retain the security protections from the September releases. Organisations should install the newest applicable update rather than attempting to choose between the security fixes and the RDS repair.

The Citrix black screen has a different recovery path

Microsoft currently describes the black-screen issue as mitigated rather than resolved. Its release-health guidance provides a Known Issue Rollback for Windows 11 24H2, 25H2 and 26H1.

For centrally managed devices, administrators must download the applicable KIR Group Policy package, install it, enable the policy and restart the device. The policy disables the change causing the problem until Microsoft supplies a permanent resolution in a future Windows update.

For a user already looking at a black screen, Microsoft documents a temporary way to regain the desktop:

  1. Open Task Manager with Ctrl+Shift+Esc.
  2. Select Run new task.
  3. Enter explorer.exe and run it.

That action starts the shell for the current session. It is not a fleet-level repair and it does not remove the condition that caused the crash.

Microsoft’s separate FSLogix known-issues page says the condition affects FSLogix 2210 hotfix 4, version 2.9.8884.27471, and later. It classifies the work as in progress and says the black screen results from explorer.exe crashing during shell start-up. Microsoft plans to address it through a future FSLogix release or a coordinated Windows release.

Do not treat every Citrix black screen as the same failure

The following split is more useful than treating every post-update login complaint as one incident.

Connections hang before the desktop session is established

Check the RDS and Winlogon events, inspect TermService and confirm whether the platform has received its applicable 14 September out-of-band update or a later cumulative release.

Authentication succeeds but the Citrix black screen remains

Check for explorer.exe crashes, identify whether the VDA uses FSLogix or Citrix Profile Management, confirm the affected Windows build and assess the Microsoft Known Issue Rollback. Test with both established and newly created profiles because Microsoft says some existing profiles appear more likely to trigger the problem.

The session works only after manually starting explorer.exe

Treat that as a diagnostic clue and temporary restoration step. It supports the shell-start failure hypothesis, but it does not demonstrate that the environment is safe to leave unchanged.

What infrastructure teams should do now

  • Separate server VDAs from desktop OS VDAs. The RDS problem spans Windows Server and client systems. Microsoft’s current black-screen record lists Windows 11 client platforms and no affected server platform.
  • Record the exact build, not only the update month. Determine whether KB5120998, KB5124008, an out-of-band repair or a later cumulative update is installed on each affected machine.
  • Confirm profile technology and version. Record whether the host uses Citrix Profile Management, FSLogix or another profile solution. For FSLogix, capture the installed version and retain the profile logs from C:\ProgramData\FSLogix\Logs\Profile.
  • Apply the RDS repair where required. Do not withhold the cumulative out-of-band update because a separate black-screen condition remains.
  • Pilot the KIR on representative VDAs. Use a small ring that includes existing profiles, multi-session behaviour where applicable and the applications users need immediately after sign-in.
  • Plan the restart. Both the Windows out-of-band update and the enterprise KIR workflow require a controlled restart to complete the change.
  • Validate the user journey. A healthy service status is not enough. Test connection establishment, authentication, shell start, profile attachment, application launch, sign-out and reconnection.
  • Keep rollback state visible. Document which VDAs received the KIR so the temporary policy can be retired cleanly when Microsoft publishes the permanent fix.

A green patch report is not the same as a healthy desktop

Citrix’s September validation report says the Windows security updates passed its testing on selected supported CVAD releases, but it also says the tests were not exhaustive and were conducted only on English-language environments. That is a useful boundary, not a contradiction.

Patch validation proves that a defined set of tests passed. It cannot reproduce every combination of Windows build, VDA release, profile technology, user history and application stack in production. The operational lesson is therefore not to distrust the security update. It is to validate the full service that depends on it.

The September incident now has two different end states. Remote Desktop Services has a published repair. The Citrix and FSLogix black-screen condition has a mitigation and a promised future fix. Infrastructure teams need to know which state their users are actually in before declaring the change complete.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *