---
title: "Windows Update error 0x80070002 or 0x80070003: update fails or will not install"
description: A cumulative update downloads, then fails or rolls back with 0x80070002 (file not found) or 0x80070003 (path not found). The cause is usually a damaged Windows Update download cache or a damaged component store. Here is how to read the logs, reset the update cache without deleting anything, and repair the component store in the right order.
url: "https://keh-tech.net/kb/windows-update-error-0x80070002-0x80070003/"
updated: "2026-10-05"
category: Troubleshooting
tags:
  - Command Prompt
  - DISM
  - Event Viewer
  - System File Checker
  - Windows
  - Windows Server
  - Windows Update
  - WSUS
---

# Windows Update error 0x80070002 or 0x80070003: update fails or will not install

A monthly update downloads, sits at "Pending install" or "Installing", and then fails. Or it installs, the PC restarts, and the update rolls back. Settings shows one of these:

```
Install error - 0x80070002
Install error - 0x80070003
```

On a server or in Event Viewer (System log, source **Microsoft-Windows-WindowsUpdateClient**) the same failure looks like this:

```
Event ID 20
Installation Failure: Windows failed to install the following update with error 0x80070002: <update name> (KB number).
```

Both codes are plain Windows file errors, not Windows Update errors as such. **0x80070002** is `ERROR_FILE_NOT_FOUND` and **0x80070003** is `ERROR_PATH_NOT_FOUND`. They say that something the update needed was not where Windows looked for it. The job is to find out what was missing, and the fix is the same in most cases: clear out the update cache, repair the component store, and try again.

**Applies to:** Windows 10, Windows 11 and Windows Server. Microsoft documents these two codes in its Windows Update error tables and in a dedicated 0x80070002 article. Run every command from an **elevated Command Prompt** (search for cmd, then **Run as administrator**). The commands use cmd syntax, so they will not work as written in PowerShell.

## What is going on

Windows Update works in two stages. The Windows Update service downloads the update into a working folder, `C:WindowsSoftwareDistribution`, and keeps its signature data in `C:WindowsSystem32catroot2`. Then the servicing stack (also called CBS, Component-Based Servicing) installs it, using the component store in `C:WindowsWinSxS`. Either stage can hit a file or path that is not there.

Microsoft lists three typical causes for 0x80070002: an earlier update that never finished and left the system half-changed, missing DLLs or system files in the component store, and registry entries that point at services or files that no longer exist. A partly downloaded or damaged cache is the cheap one to rule out first, which is why most guides start by resetting it. Antivirus that locks the update folders can also make files look missing.

## Diagnosis

### 1. Rule out the easy cases

Restart the PC and run **Settings > Windows Update > Check for updates** once more. Make sure there is plenty of free space on the system drive, and that the PC is not waiting on an earlier restart. Then run Microsoft's **Windows Update troubleshooter** (Settings > System > Troubleshoot > Other troubleshooters on Windows 11). Microsoft's own guidance says it analyses the situation and resets any update components that need it, so it is the least risky first move.

### 2. Read the real error

The code only tells you "something was not found". The logs tell you what. Windows Update no longer writes a plain text `WindowsUpdate.log`; it writes trace files that you convert. In an elevated PowerShell window:

```
Get-WindowsUpdateLog
```

This merges the trace files into a single `WindowsUpdate.log` on the desktop of the user who ran it. It is a snapshot, so run it again after each failed attempt. For install-stage failures, the servicing log is the better source:

```
notepad C:WindowsLogsCBSCBS.log
```

Search for `, error`, then match the timestamp to the failed install. Microsoft's entry for 0x80070003 says exactly this: open the latest CBS.log, search for `, error`, and match it to the time of the failure. Look for lines ending in `0x80070002 - ERROR_FILE_NOT_FOUND` and read the line just above for the file, driver or component named. On large PCs the log rolls over into `CBSPersist_*.log` or a `.cab` file in the same folder.

### 3. Match what you see to a known pattern

- **A driver .inf is named in CBS.log** (Microsoft's example is `flpydisk.inf` with "Failed installing driver updates"): a driver service key is missing from the registry. Cache resets will not help. Microsoft's fix is to export the matching key from a working PC and import it.
- **A file under WinSxS is named** (Microsoft's example is `DWrite.dll`): the component store is damaged. Go to the DISM repair in the fix.
- **Nothing specific, or the download itself stalls:** the cache reset is the right next step.
- **Many PCs fail on the same update, and they all use WSUS or Configuration Manager:** the problem may be on the server side, so check there before touching clients.

## Root cause

A file or folder the update expects is missing or damaged: in the update cache (`SoftwareDistribution`, `catroot2`), in the component store, or in the registry entries that describe a driver or service. The cache is a working area that Windows recreates by itself, which is what makes resetting it safe. The component store is not, which is why it gets repaired rather than renamed.

## The fix

**Rename, never delete.** Renaming keeps the old folders so you can put them back if something looks wrong. Renaming `SoftwareDistribution` also clears the list of installed updates shown in Windows Update history; the updates are still installed. Rename `catroot2` only. Leave the folder called `catroot` alone, because it is not part of any documented reset.

### Step 1: reset the update cache

The services involved are **Background Intelligent Transfer Service** (`bits`), **Windows Update** (`wuauserv`) and **Cryptographic Services** (`cryptsvc`). Microsoft's manual reset procedure stops these three. Cryptographic Services must be stopped, or the `catroot2` rename fails. Many online guides also stop `msiserver` (Windows Installer). It is not on Microsoft's list, and you do not need it for this reset.

```
net stop bits
net stop wuauserv
net stop cryptsvc

ren %systemroot%SoftwareDistribution SoftwareDistribution.old
ren %systemroot%System32catroot2 catroot2.old

net start cryptsvc
net start wuauserv
net start bits
```

If a rename says the folder is in use, the service did not stop. Run `sc query wuauserv` to check, and look for security or backup software that scans these folders. If a `.old` folder is already there from an earlier attempt, rename to a new name instead of overwriting. Then check for updates again. Windows creates fresh folders on the first scan, and the first scan can take several minutes.

### Step 2: repair the component store, then the system files

If the update still fails, repair the component store with DISM (Deployment Image Servicing and Management), then check system files with SFC (System File Checker). The order matters: SFC takes its good copies from the component store, so repair the store first. Microsoft lists exactly this pair of commands for component store corruption.

```
DISM.exe /Online /Cleanup-Image /RestoreHealth
sfc /scannow
```

DISM normally downloads replacement files through Windows Update, which is one reason to do the cache reset first. Restart when both finish, and try the update again. If DISM cannot find its source files, run it again after a restart, or point it at a matching Windows image with the `/Source` option. Take care that the image is the same Windows version and edition.

### Step 3: if it is still failing

- Go back to CBS.log and read the error again. A new attempt can fail on a different file, and the log will name it.
- Install the update by hand. Download the standalone package for that KB from the Microsoft Update Catalog and run it. The error message is often clearer than the one Windows Update shows.
- Check for antivirus or backup software that filters file access. Microsoft names this as a common cause of the related error 0x80070020. Try a clean boot and run the update again.
- On a managed PC, check the update source. Microsoft has separate guides for WSUS client agents and for software update scan failures in Configuration Manager. Both include the same cache rename as a step.

Microsoft's last-resort one-liner, `rd /s /q %systemroot%SoftwareDistribution`, deletes the cache outright. It works, but it leaves you no way back, and renaming does the same job, so use the rename.

## Verification

- Open **Settings > Windows Update** and select **Check for updates**. The update should download and install without stopping.
- Confirm that Windows created new folders: `dir C:WindowsSoftwareDistribution` and `dir C:WindowsSystem32catroot2` should both exist and be filling up.
- After a restart, check the System log for a new Windows Update Client event saying the update installed, not a new Event ID 20.
- Check the update is in the installed list: `Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5` in PowerShell.

A clean restart and no rollback is the real test, because some failures only appear during the restart phase of the install.

Once the PC is updating normally, delete the `.old` folders to get the space back. Leave them for a week or two if you want a way back.

## Notes

- **Things not to use:** registry cleaners (they damage the servicing keys), and the command `usoclient StartScan`. That command is not documented by Microsoft and does not report whether it worked. Use Settings, or the update tools your organisation provides.
- **0x80070003 and CBS.log:** Microsoft describes it as "the servicing stack cannot access a specific path", with no single fix. The log is how you find the path.
- **Deeper reset:** Microsoft also documents a longer manual reset that re-registers many DLLs and resets the service security descriptors with `sc.exe sdset`. The sdset step overwrites the security settings on the BITS and Windows Update services, and Microsoft says to skip it unless the other steps failed. It is beyond this article.
- **Back up first on important machines.** Microsoft's own 0x80070002 article starts by asking you to back up the OS disk. On a server, take a checkpoint or snapshot.

**Still stuck on 0x80070002?** Post the failing KB number and the lines from CBS.log around the error in [The Patch Panel](/community/help/) and we will read it with you. The best answer earns points on [Top of the Stack](/leaderboard/).
