Windows Update Errors 0x80070643, 0x80070005 and 0x800f0922: What Each One Means and How to Fix It

Reviewed by IT Cares technicians · Updated October 1, 2026

Laptop showing a Windows Update failure warning for error codes 0x80070643, 0x80070005 and 0x800f0922
Three Windows Update codes, three different causes. Match the code to the fix instead of guessing.

Quick fix (5 steps)

  1. Restart, disconnect any VPN, and make sure the C: drive has at least 15 GB free.
  2. Open Settings, System, Troubleshoot, Other troubleshooters, Windows Update, Run.
  3. Open Command Prompt as administrator and run DISM /Online /Cleanup-Image /RestoreHealth, then sfc /scannow, then restart.
  4. For 0x80070643 only: run reagentc /info. If the recovery partition is small or Windows RE is disabled, jump to the WinRE section.
  5. Retry the update. If it still fails, use the code-specific sections: 0x80070643, 0x80070005, 0x800f0922.

What these three Windows Update error codes actually mean

0x80070643, 0x80070005 and 0x800f0922 are three separate failures that happen to appear in the same place, Windows Update. The first is a generic installation failure, the second is "access denied", and the third is a servicing (CBS) failure. Treating them as one problem is why generic "fix Windows Update" videos often fail.

Each code is a Windows error number written in hexadecimal. The part after "0x8007" in the first two comes from the standard Win32 error table: 0x643 (1603 in decimal) is ERROR_INSTALL_FAILURE, and 0x5 is ERROR_ACCESS_DENIED. The third, 0x800f0922, belongs to the component-based servicing stack, the part of Windows that installs, stages and commits updates. Knowing which family the code belongs to tells you where to look: the installer, the permissions, or the servicing store.

CodePlain meaningMost common real causeFirst thing to try
0x80070643Installation failed (generic)Recovery (WinRE) partition too small, damaged .NET or Windows Installer, failed Defender platform updatereagentc /info, then DISM and SFC
0x80070005Access deniedWrong permissions, third-party security software, no admin rights, profile or disk problemReset update cache, check security software, run as administrator
0x800f0922Servicing operation failedFull System Reserved or EFI partition, VPN or proxy, corrupt component store, .NET 3.5 feature failureDisconnect VPN, free space, DISM RestoreHealth

The honest summary is that DISM and SFC help with all three, but only the right code-specific step actually ends the loop. If you want the deeper single-code pages, we also maintain focused guides for error 0x80070005, Windows 11 update failure 0x800f0922 and the related error 0x80073712. This article is the combined, decision-tree version: it helps you work out which family you are in and gives the commands in the right order.

Why people see these codes together

The same update often throws different codes on different tries, because a failure at one layer exposes a failure at the next. A permissions problem can leave a half-staged update, which then fails with a servicing error on the following attempt, and a servicing error can end with a generic install failure. That is why a user may report all three within a week.

A typical sequence looks like this. A cumulative update downloads, then fails at "Installing" with 0x80070005 because a security product locked a file. The retry runs on a partly staged update and fails with 0x800f0922 when the component store rejects the incomplete package. After a few more attempts the monthly update fails with 0x80070643 because the stale pending state blocks the installer. Each message is accurate for its moment, but the root cause is the first one. When you see several codes on one machine, fix the earliest failure in Update history first, not the latest.

How to read your own Update history

Open Settings, Windows Update, Update history. Under "Failed updates" Windows lists the update name, its KB number, the date and the error code. Sort mentally by date and look for the oldest failure. Also note the type of update: a cumulative update, a .NET Framework update, a Defender platform update, a driver, or a feature update. A failing .NET update points at .NET repair. A failing cumulative update after a recovery-environment warning points at the WinRE partition. A failing feature update points at disk space, drivers and the System Reserved partition.

What is not the cause

Before you start: a safe routine that prevents most of the damage

Back up first, free disk space, and note your recovery key, because several of the fixes below touch system files or partitions. Ten minutes here protects you from the rare case where a repair step goes wrong or a power cut hits mid-operation.

  1. Back up your files. Copy documents, photos and desktop files to an external drive, or confirm your cloud folder is truly synced by opening it on another device. Our short comparison of data recovery versus data backup explains why a tested backup beats hoping recovery works.
  2. Free 15 to 20 GB on C:. Use Settings, System, Storage, Temporary files. A nearly full system drive causes both 0x800f0922 and 0x80070643 more often than people expect.
  3. Plug in the laptop and disconnect docks, USB drives, printers and any VPN.
  4. Save your BitLocker key if the drive is encrypted. Find it at the Microsoft account recovery key page or in your work account. Partition and boot changes can trigger a recovery prompt.
  5. Create a restore point by searching "Create a restore point", selecting your system drive and choosing Create. It will not undo partition changes, but it protects against many driver and registry mistakes.

Pre-repair checklist

  • ☐ Files backed up and verified on a second device or drive
  • ☐ At least 15 GB free on C:
  • ☐ Laptop plugged in, VPN off, extras unplugged
  • ☐ BitLocker or device-encryption key saved if applicable
  • ☐ Failed update name, KB number and code written down
  • ☐ Restore point created

If you cannot complete the checklist, for example you have no backup and the machine holds client files, pause here. A remote technician can clone the drive or copy the data first. Stopping early is cheaper than data recovery, which we cover in data recovery after a Windows update or reinstall.

Fixes that work for all three codes (do these first)

Start with the five universal repairs in this order: restart and clean the environment, run the troubleshooter, repair with DISM, repair with SFC, then reset the update cache. They are safe, reversible and solve a large share of cases before you need any code-specific step.

Step 1: Restart and clean the environment

Restart the computer fully (not Sleep, not Fast Startup). Choose Restart from the Start menu, because shutting down with Fast Startup enabled can preserve a broken state. Disconnect any VPN client, close remote-access tools, and pause heavy sync clients for the duration. If the machine is a work PC, check that you are not blocked by a policy that pins updates.

Step 2: Run the Windows Update troubleshooter

Open Settings, System, Troubleshoot, Other troubleshooters and press Run next to Windows Update. It resets some services and clears a few flags. It rarely fixes the deepest causes, but it costs one minute and sometimes gets the job done.

Step 3: Repair the component store with DISM

Right-click the Start button, choose Terminal (Admin) or Command Prompt (Admin), and run these commands one at a time:

DISM /Online /Cleanup-Image /CheckHealth
DISM /Online /Cleanup-Image /ScanHealth
DISM /Online /Cleanup-Image /RestoreHealth

RestoreHealth downloads clean copies of damaged system components from Windows Update and can take 10 to 30 minutes. It may sit at 20 percent or 62 percent for a long time, which is normal. If it reports error 0x800f081f, the source files could not be found: mount the official Windows ISO and run DISM /Online /Cleanup-Image /RestoreHealth /Source:WIM:D:\sources\install.wim:1 /LimitAccess, replacing D: with the mounted drive letter and 1 with the image index that matches your edition. Microsoft documents the DISM options on its repair a Windows image page.

Step 4: Run System File Checker

After DISM finishes, run sfc /scannow in the same administrator window. SFC compares protected system files against the component store and replaces bad ones. Run it twice if the first run says it fixed files. If it reports that it found corrupt files it could not fix, check the CBS log at C:\Windows\Logs\CBS\CBS.log and go back to DISM with an ISO source. Restart afterwards.

Step 5: Reset the Windows Update cache

This clears the downloaded and staged update files so Windows starts fresh. In an administrator Command Prompt:

net stop wuauserv
net stop cryptSvc
net stop bits
net stop msiserver
ren C:\Windows\SoftwareDistribution SoftwareDistribution.old
ren C:\Windows\System32\catroot2 catroot2.old
net start wuauserv
net start cryptSvc
net start bits
net start msiserver

If a rename fails with "access denied", that is a clue for 0x80070005, which we cover below. Otherwise, restart and check for updates again. Windows rebuilds both folders automatically. You can delete the .old folders after a few successful updates; keep them until then in case you need to look at old logs.

Do not skip the order

Running the cache reset before DISM and SFC can look faster, but a damaged component store will simply poison the fresh cache. Repair first, reset second. The sequence above takes 30 to 50 minutes on a typical laptop and is the same sequence a technician follows.

Diagnose which code family you have in 5 minutes

The quickest diagnosis combines three checks: the exact error code in Update history, the output of reagentc /info, and the free space on your system and recovery partitions. Together they point to the right section instead of sending you through every fix.

SymptomLikely familyGo to
Cumulative update fails, "Windows RE" or recovery warnings, older PC with a small recovery partition0x80070643 (WinRE)0x80070643 section
.NET Framework or Defender platform update fails with 0x800706430x80070643 (installer or .NET)0x80070643 section
Renaming SoftwareDistribution is denied, or a manual installer says access denied0x800700050x80070005 section
Third-party antivirus, disk encryption or "security suite" installed recently0x800700050x80070005 section
Feature update fails near 85 to 100 percent and rolls back0x800f09220x800f0922 section
Enabling .NET Framework 3.5 fails0x800f09220x800f0922 section
Works on home Wi-Fi, fails on work VPN0x800f09220x800f0922 section

Run the three diagnostic commands

In an administrator terminal, run:

reagentc /info
diskpart
  list disk
  list volume
  exit
wmic logicaldisk get caption,freespace,size

If wmic is missing on your build, use Get-Volume in PowerShell instead. In the reagentc output, look at "Windows RE status" (Enabled or Disabled) and "Windows RE location" (for example \\?\GLOBALROOT\device\harddisk0\partition4\Recovery\WindowsRE). The number after "partition" tells you which partition holds it. Compare that with Disk Management (right-click Start, Disk Management) to see its size and free space. A recovery partition of 500 MB or less that is nearly full is the classic 0x80070643 culprit.

Read the logs when the code alone is not enough

For a servicing failure, open C:\Windows\Logs\CBS\CBS.log and search for the word "Error". For an install failure, Event Viewer, Windows Logs, Setup and Application often show the failing component. For Windows Update client details, run PowerShell Get-WindowsUpdateLog, which writes a readable file to your desktop. You do not need to read all of it. Search for the KB number and the HRESULT near it. The lines nearby usually name the file, service or partition that failed, which turns a vague code into a specific target.

Identify your disk layout

Two layouts matter. A GPT/UEFI disk has an EFI System Partition (usually 100 to 260 MB), a Microsoft Reserved partition, the C: partition, and a recovery partition. An MBR/BIOS disk has a System Reserved partition (100 to 500 MB) and C:, with the recovery partition sometimes at the end. Run msinfo32 and read "BIOS Mode": UEFI means GPT in nearly all modern installs, Legacy means MBR. The correct commands in the WinRE section differ for each, so do not skip this.

Illustration of a disk with a small highlighted recovery partition being enlarged to fix a Windows Update error

Fixing error 0x80070643

Error 0x80070643 is a generic "installation failed" result, and the cause you can actually act on is usually one of four: a small Windows Recovery Environment partition, a damaged .NET Framework, a broken Windows Installer service, or a failed Defender platform update. Work through them in that order of likelihood for cumulative updates, and in reverse order if the failing item is a .NET or Defender update.

Cause A: the WinRE partition is too small

Windows keeps a small recovery image (WinRE) on a hidden partition. In January 2024 Microsoft published KB5034441, a Windows Recovery Environment update for Windows 10 that failed with 0x80070643 on many PCs because the recovery partition did not have enough free space. Microsoft's guidance at the time described needing roughly 250 MB of free space in that partition. Similar recovery-image updates have been issued since, and the same pattern appears in recent Q&A threads for Windows 11, including a Microsoft Q&A thread about 24H2. Check the current Microsoft notice for your exact KB before acting, since requirements can change between releases.

First confirm the diagnosis with reagentc /info. If Windows RE status is Enabled and the location points to a partition that Disk Management shows as, say, 500 MB with under 250 MB free, you have the classic case. If Windows RE shows Disabled, or the location is blank, the recovery environment itself is not registered, which also blocks the update.

Do not run this if

Do not resize partitions if the drive is failing or reporting SMART warnings, if the disk is encrypted with BitLocker and you have not saved the key, if the machine is a managed work PC (ask your IT team, they may have a script), or if you cannot identify the recovery partition with certainty. In those cases skip to the manual install or call for help.

Cause B: Windows RE is simply disabled

Try the cheap fix before touching partitions. In an administrator terminal run:

reagentc /disable
reagentc /enable
reagentc /info

If /enable succeeds and the status becomes Enabled, retry the update. If it fails with an error about a missing Winre.wim, the recovery image is absent and needs to be restored from an ISO, which a technician can do in a few minutes by copying winre.wim out of the install image. Microsoft documents the tool on its REAgentC page.

Cause C: a damaged .NET Framework or Windows Installer

If the failing update is a ".NET Framework cumulative update" or a Defender platform update, the partition is not the culprit. Do this instead:

  1. Open Control Panel, Programs and Features, Turn Windows features on or off. Untick .NET Framework 3.5 and 4.8 Advanced Services, restart, then tick them again and let Windows reinstall them.
  2. Download Microsoft's .NET Framework Repair Tool from the official Microsoft site, run it and accept the recommended repairs.
  3. In an administrator terminal run sc query msiserver. If the service is missing or stuck, run msiexec /unregister followed by msiexec /regserver, and restart.
  4. For a failing Defender platform update, open Windows Security, Virus and threat protection, Protection updates, and select Check for updates. If it fails, remove leftover third-party antivirus and retry.

Cause D: pending reboot or stale pending.xml

An interrupted earlier install can leave a pending operation that blocks the next one. Restart twice. If it persists, check whether C:\Windows\WinSxS\pending.xml exists. Do not delete it blindly. A technician can safely move it or run DISM /Online /Cleanup-Image /RevertPendingActions, but be aware that command is meant for Windows that is not fully installed and should not be a first choice.

Resizing or recreating the WinRE partition step by step

The permanent fix for the small-recovery-partition cause is to disable WinRE, shrink the C: partition, delete the old recovery partition, create a larger one with the correct type, and re-enable WinRE. The steps below follow the approach in Microsoft's published guidance, but verify the GUID and attribute values against the current Microsoft page before running them, since a wrong partition type can make the recovery environment unusable.

Stop before you touch diskpart

Back up your files first. Deleting or resizing the wrong partition can make a PC unbootable and its data hard to recover. If you are not 100% sure which partition is which, or the partitions do not look like the layout described below, do not continue. Call a technician: a remote or on-site session costs far less than a data recovery job.

Step 1: Record your starting state

Run reagentc /info and note the partition number. In Disk Management, confirm that the recovery partition sits directly after C: (to the right of it). If other partitions sit between them, the standard shrink approach will not work without third-party tools, and you should stop and get help.

Step 2: Disable WinRE and open diskpart

reagentc /disable
diskpart
list disk
select disk 0
list partition

Identify the C: partition (largest) and the recovery partition (type Recovery, often 450 to 600 MB). Select the C: partition with select partition X (where X is the number you identified) and make sure it is the right one with detail partition.

Step 3: Shrink C: by 250 MB or more

shrink desired=250 minimum=250

If you want headroom for future updates, use 500 instead. A larger recovery partition costs you a small slice of disk and prevents repeat failures. If shrink fails because of unmovable files, run Disk Cleanup, disable hibernation temporarily with powercfg /h off, restart, and try again.

Step 4: Delete the old recovery partition

select partition Y
delete partition override

Replace Y with the recovery partition number you confirmed. Triple-check it. Deleting the wrong partition can make Windows unbootable. This is the step where most disasters happen.

Step 5: Create the new partition

For a GPT/UEFI disk:

create partition primary
format quick fs=ntfs label="Windows RE tools"
set id="de94bba4-06d1-4d40-a16a-bfd50179d6ac"
gpt attributes=0x8000000000000001
exit

For an MBR/BIOS disk the id differs:

create partition primary
format quick fs=ntfs label="Windows RE tools"
set id=27
exit

The new partition takes the space you freed from C: when it is created right after the shrink. If you shrank by 250 MB and need it all, the new partition will use all unallocated space.

Step 6: Re-enable WinRE and verify

reagentc /enable
reagentc /info

Status should be Enabled and the location should point to the new partition. Retry Windows Update. If the update still fails, check reagentc /info again, and consider a manual install from the Microsoft Update Catalog in the final section.

ApproachRiskTimeBest for
Wait for Microsoft to ship a fix or scriptVery lowNoneNon-critical PCs, no urgency
reagentc /disable then /enableVery low2 minutesDisabled WinRE
Manual diskpart resize (above)Medium (typo or wrong partition)20 to 40 minutesTechnical users with a backup
Partition manager toolMedium15 to 30 minutesLayouts with partitions in between
Remote technicianLowOne 60-minute sessionBusiness PCs or no backup

Fixing error 0x80070005 (access denied)

Error 0x80070005 means Windows or an installer tried to read, write or start something and was refused. The refusal comes from file or registry permissions, a security product that blocked the action, a missing administrator token, or a damaged user profile. Fixing it is mostly about finding who said no.

Check 1: Are you really running with admin rights?

If the error appears when you run a manual installer or a script, right-click it and choose Run as administrator. If your account is a standard user on a family or work computer, sign in with an administrator account. On a managed PC, a policy may block the installer on purpose, and the right fix is a request to your IT team, not a workaround.

Check 2: Security software

Third-party antivirus, endpoint protection, "tune-up" software and some disk encryption tools can lock system files or block the update service. Temporarily disable real-time protection of the third-party product (not Microsoft Defender) for the update, install, then re-enable it. If that works, check the vendor's exclusion list and add the Windows Update folders as documented. Never leave protection off. If you have two security products installed, remove one: running two real-time scanners is a common source of access-denied errors. Our free antivirus comparison helps you pick a single product to keep.

Check 3: Permissions on the update folders

The SoftwareDistribution and catroot2 folders must be accessible to SYSTEM and Administrators. Open an administrator terminal and run:

icacls C:\Windows\SoftwareDistribution /grant "NT SERVICE\TrustedInstaller":(OI)(CI)F
icacls C:\Windows\SoftwareDistribution /grant SYSTEM:(OI)(CI)F
icacls C:\Windows\SoftwareDistribution /grant Administrators:(OI)(CI)F

This restores the standard access that the update service expects. If a rename in the cache reset earlier was refused, this often unblocks it. Do not run icacls with /T across the whole Windows folder; broad permission changes cause more damage than they cure.

Check 4: Services and their accounts

Press Windows + R, type services.msc and check that Windows Update, Background Intelligent Transfer Service, Cryptographic Services and Windows Installer are not Disabled. Windows Update should be Manual (Trigger Start) or Automatic, and the Log On account should be Local System. A service set to run as a specific user, which some "optimizers" do, will cause access denied. Reset it to Local System and restart the service.

Check 5: Disk errors and a damaged profile

Run chkdsk C: /scan in an administrator terminal. A read-only scan catches file system errors without scheduling an offline repair. If errors are found, run chkdsk C: /f and restart. For a profile problem, create a new local administrator account, sign in, and try the update from there. If it works, the old profile was the issue and you can migrate your data to the new one.

Check 6: The registry key and the Microsoft Store variant

If 0x80070005 appears in the Microsoft Store or when installing a specific app, rather than Windows Update, reset the Store cache with wsreset.exe and re-register the app packages from PowerShell. The permission cause is the same family, but the folders (WindowsApps, the Store cache) are different. Our dedicated 0x80070005 page covers those variants in more detail.

Safety note on permissions

Be careful with any guide that tells you to take ownership of C:\Windows or give Everyone full control. That fixes the error by removing protections, and it leaves your PC less secure and sometimes unbootable. Restore standard permissions only on the specific folder named in the log.

CheckEffortFixes it when
Run as administrator1 minuteManual installers fail, standard user account
Disable third-party security briefly5 minutesAntivirus is locking files
icacls on SoftwareDistribution5 minutesCache folder cannot be renamed or written
Reset service accounts5 minutes"Optimizer" changed service logon
chkdsk and new profile20 to 40 minutesFile system or profile corruption

Fixing error 0x800f0922

Error 0x800f0922 usually appears when an update reaches the final stage and cannot be committed, most often because the System Reserved or EFI partition is full, a VPN or proxy interrupts the connection to Microsoft, or the component store is damaged. Fix the cheap network and space causes first, then repair the store, then deal with the partition.

Cause A: VPN, proxy or firewall

Some updates must contact Microsoft servers during installation. A full-tunnel VPN, a corporate proxy or an aggressive firewall can drop that connection and produce 0x800f0922. Disconnect the VPN, turn off any manual proxy under Settings, Network and Internet, Proxy, and retry on a home network. If it works there, the cause is your work network and the remedy belongs to your IT team: ask them to allow Windows Update endpoints or let the machine update off-VPN.

Cause B: the System Reserved or EFI partition is full

Feature updates write boot files to the System Reserved partition (MBR) or the EFI System Partition (GPT). If it is nearly full, often because old font files or third-party boot tools filled it, the update rolls back around 90 percent. Check it by opening Disk Management, or run mountvol S: /S to mount the EFI partition as S: and then dir S: /s to see what is in it. Do not delete anything in the EFI folder unless you know what it is. Common safe candidates are leftover font files in EFI\Microsoft\Boot\Fonts that are not required for boot. If this feels risky, it is: a technician can free space safely, or resize the partition with a proper tool after a backup.

When you finish, unmount the partition with mountvol S: /D. On a PC where the EFI partition is only 100 MB, a feature update is the most likely time to hit the limit, and it is why 0x800f0922 appears so often during version upgrades such as the one described in our Windows 11 0x800f0922 page.

Cause C: .NET Framework 3.5 or an optional feature

If the error shows up when enabling .NET Framework 3.5 from Windows Features, the usual causes are blocked access to Windows Update, a policy that redirects source files, or corrupt store files. Run DISM with the ISO as the source: DISM /Online /Enable-Feature /FeatureName:NetFx3 /All /LimitAccess /Source:D:\sources\sxs, replacing D: with your mounted ISO drive. This installs the feature from the local files and skips the network.

Cause D: a damaged component store

Repeat the DISM RestoreHealth and SFC sequence from earlier. If DISM cannot repair, use the ISO as the repair source. As a last resort before an in-place upgrade, run DISM /Online /Cleanup-Image /StartComponentCleanup to remove superseded components, then retry. Avoid /ResetBase unless you understand that it removes the ability to uninstall installed updates.

Manual install and in-place repair when the fixes do not stick

If the update still fails after the code-specific repairs, install it manually from the Microsoft Update Catalog, and if that fails too, run an in-place repair upgrade from the official ISO. Both methods bypass the parts of Windows Update that are failing and keep your files and apps.

Option 1: Install the standalone package

  1. Note the KB number from Update history, for example the KB listed next to the failed entry.
  2. Open the Microsoft Update Catalog and search for that KB number.
  3. Pick the entry that matches your Windows version (23H2, 24H2, 25H2) and architecture (x64 for most PCs, ARM64 for Copilot+ Arm devices). Check your build with winver and systeminfo.
  4. Download the .msu file and double-click it, or install it from an administrator terminal with wusa.exe C:\path\to\update.msu /quiet /norestart. Restart afterwards.

A standalone install fails differently from a Windows Update install, and the message is often more specific. If wusa reports a missing prerequisite, install the previous servicing stack update or the latest cumulative update it names. Some updates are delivered as .cab files rather than .msu. For those, use DISM /Online /Add-Package /PackagePath:C:\path\update.cab.

Option 2: In-place repair upgrade

This reinstalls Windows over itself while keeping your files, apps and settings, and replaces damaged system files and the component store. It is the most reliable fix for stubborn servicing and permission corruption.

  1. Download the Windows 11 ISO or Installation Assistant from Microsoft's download page. Use the same language and a version that is the same or newer than your current build.
  2. Right-click the ISO, choose Mount, and open it in File Explorer.
  3. Run setup.exe from the mounted drive. Choose "Keep personal files and apps" when prompted. Pick "Not right now" for the dynamic updates step if the earlier ones were failing.
  4. Allow 45 to 90 minutes and several restarts. Do not power off, even if the progress bar looks stuck.
  5. After it finishes, run Windows Update again and the earlier failure should be gone.

On a PC with a very small EFI or System Reserved partition, setup may still fail with 0x800f0922. In that case free space in the EFI partition or resize it first, as described above, then retry. If you are mid-way through the Windows 11 feature-update cycle, our Windows 11 25H2 update guide covers version-specific traps.

Option 3: Last resort, reset or clean install

If the in-place repair fails, the system has deeper corruption or a hardware cause (failing SSD, bad RAM). Test the disk and memory first. Then use Settings, System, Recovery, Reset this PC, or clean install from USB after backing up. A reset that keeps files is faster, but a clean install is the cleaner baseline. A clean install also gives Windows a chance to create a modern, correctly sized recovery partition. That is one genuine advantage on old machines, whose partitions were laid out years ago. See our Windows 11 speed guide for what to do after a fresh install.

Realistic scenarios (illustrative, not real client cases)

The same code can have very different causes, so the quickest route is to match your situation to a pattern. The three realistic scenarios below show how the fixes combine in practice. They are illustrative composites and are not records of real clients.

Scenario 1: The home laptop that fails every Patch Tuesday

A five-year-old laptop with a 512 GB SSD has failed the monthly cumulative update for three months with 0x80070643. reagentc /info shows Windows RE enabled on partition 4. Disk Management shows a 523 MB recovery partition with about 120 MB free, below the roughly 250 MB that was cited for the KB5034441-style update. C: has 61 GB free. The owner backs up photos to an external drive, saves the BitLocker key, disables WinRE, shrinks C: by 500 MB, recreates the partition with the correct GPT type and re-enables WinRE. The next Patch Tuesday update installs. Total time: about 35 minutes, cost: nothing but a USB drive the owner already had.

Scenario 2: The office PC with 0x80070005 after a security suite change

A small accounting office replaces its antivirus with a new endpoint product, and the next Windows Update on one workstation fails with 0x80070005. Renaming SoftwareDistribution is denied. The old antivirus was only partly uninstalled, so two real-time scanners are fighting over the same files. The fix: use the old vendor's removal tool, restart, reset the update cache, and confirm only the new product is active. The workstation updates normally and the other PCs, which had a clean uninstall, were never affected. Time: about 40 minutes remote, within a single 60-minute session.

Scenario 3: The remote employee on a VPN with 0x800f0922

A remote employee's work laptop tries to install a feature update, reaches about 90 percent, rolls back and reports 0x800f0922. The always-on VPN forces all traffic through the head office, and the update needs to contact Microsoft during the final stage. On the employee's home network with the VPN paused (with IT approval), the same update installs. Because the EFI partition was also only 100 MB with 4 MB free, the support team frees space in the EFI font folder at the same time. Result: a one-off VPN exception policy and a documented procedure for the other twenty laptops, instead of twenty separate failures.

ScenarioCodeRoot causeFix that worked
Home laptop, monthly failures0x80070643Full recovery partitionRecreate larger WinRE partition
Office PC after antivirus change0x80070005Two real-time scannersClean removal, cache reset
Remote employee0x800f0922VPN plus full EFI partitionUpdate off-VPN, free EFI space

What this costs in Canadian dollars: DIY versus paying a technician

Most of these fixes cost nothing but time, and a paid session only makes sense when your data is at risk, the PC is for business, or you have already spent a few hours without progress. The figures below are realistic ranges in CAD, not quotes, and prices at other providers vary.

RouteTypical cost (CAD)Your timeRisk
DIY with DISM, SFC and cache reset0 $1 to 2 hoursLow
DIY partition resize with diskpart0 $ to 20 $ (USB backup drive)1 to 3 hoursMedium
Walk-in repair shop (varies by shop)Often 60 $ to 150 $, plus drop-off timeHalf a day without your PCLow
IT Cares remote Expert Consultation119.99 $ for 60 minutesAbout an hour at your screenLow
New computer to dodge the problem800 $ to 1,500 $+Days to migrateUnnecessary in nearly every case

Think about what the hour is worth. If you run a clinic, a shop or a bookkeeping practice, a PC that cannot install security updates is also a compliance concern, and your own hour is worth more than the consultation. If you are a student or a retiree with a time-rich afternoon, the DIY route is a good way to learn. The mistake to avoid is the middle path: paying for a "PC cleaner" subscription of 40 $ to 90 $ a year that promises to fix update errors. Those products rarely address the real causes in this article.

The hidden cost of waiting

An update that fails every month is also a security delay. Each missed cumulative update leaves known vulnerabilities in place. For a business, one compromised workstation costs far more than a consultation. Even if you choose to defer the repair, keep the machine away from risky downloads and email attachments until it is patched.

Printable troubleshooting checklist

Use this checklist in order and tick each box before moving on, so you never repeat a step or skip the one that matters. Keep it next to the PC, or paste it into a note.

Windows Update error checklist

  • ☐ Code and KB noted from Update history (oldest failure first)
  • ☐ Backup done, BitLocker key saved
  • ☐ 15 GB or more free on C:, VPN off, restart done
  • ☐ Windows Update troubleshooter run
  • ☐ DISM RestoreHealth finished, SFC clean
  • ☐ Update cache reset (SoftwareDistribution and catroot2)
  • ☐ 0x80070643: reagentc /info checked, recovery partition size confirmed
  • ☐ 0x80070005: security software checked, permissions on update folders reviewed
  • ☐ 0x800f0922: VPN and proxy off, EFI or System Reserved space checked
  • ☐ Standalone package from the Update Catalog tried
  • ☐ In-place repair upgrade tried
  • ☐ Disk and memory tested if everything else failed

How to stop these errors from coming back

Prevention comes down to four habits: keep free space, keep one security product, avoid "optimizer" tools, and update regularly instead of in big batches. Small monthly updates fail less often than a pile of six months of updates installed at once.

Official resources worth bookmarking

The most reliable references are Microsoft Learn pages for DISM, REAgentC and Windows Update troubleshooting, plus the Microsoft Update Catalog for manual downloads. They change over time, so check the date of any guide, including this one.

When to call a professional

Call a technician if the PC holds business data, you have no backup, DISM cannot repair the store, the disk shows errors, or you are about to delete a partition you cannot identify. Those are the moments where a small mistake becomes data loss, and where a one-hour session is cheaper than recovery.

IT Cares has provided remote support from Quebec and across Canada since 2014. We connect to your device, you watch, we fix it and explain what we changed. A single Expert Consultation is 119.99 $ CAD for 60 minutes. Call 1 (888) 711-9428 and a technician can tell you in a minute whether your case fits a single session.

Still stuck? Get a technician on it now

Remote support from IT Cares: we connect to your device, fix it with you watching, and explain what happened.

Frequently asked questions

What does Windows Update error 0x80070643 mean?
0x80070643 is ERROR_INSTALL_FAILURE, a generic installation failure. The most common real cause is a Windows Recovery Environment partition that is too small to hold the updated recovery image, which became widely known with KB5034441 in January 2024. Other causes include a damaged .NET Framework, a broken Windows Installer service, or a failed Microsoft Defender platform update.
What does error 0x80070005 mean?
0x80070005 is E_ACCESSDENIED. Windows or the installer was refused access to a file, folder, registry key or service. Typical causes are wrong permissions on the SoftwareDistribution folder, third-party antivirus or security software blocking the installer, a disk or user profile problem, or running a manual installer without administrator rights.
What does error 0x800f0922 mean?
0x800f0922 is a servicing failure (CBS) that most often points to a nearly full System Reserved or EFI system partition, an active VPN or proxy that blocks the connection to Microsoft servers, or corrupt component store files. It also appears when enabling .NET Framework 3.5 or other optional features fails.
Is the 0x80070643 error dangerous?
No. It means one update did not install, not that your PC is infected or broken. The risk is that the missing security update leaves a known vulnerability open. Fix it when you can, and keep other updates installing normally in the meantime.
How big should the Windows recovery partition be?
Microsoft's guidance for the KB5034441 problem was that the recovery partition needed roughly 250 MB of free space for the update. Many older installs created a 450 MB or smaller partition that is largely full. Running reagentc /info and Disk Management shows your actual size. Treat the 250 MB figure as the commonly cited requirement and check the current Microsoft notice for your update.
Can I ignore 0x80070643 and skip the update?
You can for a short time, but you should not make it permanent. The update will keep trying and failing, and later cumulative updates can fail the same way. If the recovery environment cannot be updated safely, some vulnerabilities in that component remain, so plan the fix.
Will resizing the recovery partition delete my files?
Done correctly, no. Shrinking C: and recreating the recovery partition does not touch your documents. But any partition change carries risk from power loss or a typo in diskpart, so back up first and never delete a partition you have not positively identified.
I have BitLocker. Does that matter?
Yes. Suspend BitLocker before changing partitions or the boot configuration, and make sure you have the recovery key saved. Our guide on the BitLocker recovery key after a Windows update explains where to find it.
Should I download a 'Windows Update fixer' tool?
No. Free fixers found through search results are a common source of malware and upsells. Use the built-in troubleshooter, DISM, SFC and the official Microsoft Update Catalog instead.
Why do these errors keep coming back every month?
Because the cause was never fixed. A full recovery partition, corrupt component store or permission problem blocks every new cumulative update in the same way. Fix the root cause once and the monthly failures stop.
How do I find the failed update's KB number?
Open Settings, Windows Update, Update history. Failed updates are listed with their KB number and error code. You can also run Get-WindowsUpdateLog in PowerShell, which writes a readable WindowsUpdate.log to your desktop.
When is an in-place repair upgrade better than more troubleshooting?
If DISM fails to repair the component store, or you have tried the cache reset and manual install and still see the error, an in-place repair upgrade from the official ISO keeps your files and apps and replaces damaged system files. It is usually faster than hours of trial and error.
What is the cost of getting a technician to fix it?
IT Cares offers a single Expert Consultation at 119.99$ CAD for 60 minutes, by remote session. Most update error cases fit in one session. Costs and times for on-site visits vary, so ask when you call.

Sources and official references

Last verified: October 1, 2026

Need Help?