Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Free Fix 0x80245001

0x80245001 and 0x80245003: the update redirector cab cannot be used

10 min read Updated October 4, 2026 Windows Update & Setup

Fix it now

Before any scan happens, Windows Update downloads and parses a small signed cabinet that tells it which update service applies to this device. Microsoft publishes 0x80245001 as the redirector XML failing to load, and 0x80245003 as a downloaded cab whose redirector ID is lower than the cached one. Clear the cache, fix the clock, and stop anything rewriting the download.

Run these in an elevated Command Prompt, in order

w32tm /resync
net stop wuauserv
net stop bits
net stop cryptsvc
ren C:\Windows\SoftwareDistribution SoftwareDistribution.old
ren C:\Windows\System32\catroot2 catroot2.old
net start cryptsvc
net start bits
net start wuauserv
  1. Check the result of the time sync with w32tm /query /status. The cab is signed, and a machine whose clock is badly wrong will reject content that is perfectly valid.
  2. Scan again from Settings, Windows Update and see whether the code changes. A different code after the cache reset means you have moved past this stage.
  3. If it persists, look at what sits between the device and Microsoft. Ask for the update endpoints to be excluded from TLS inspection rather than merely allowed through.
  4. Confirm what the machine account itself uses for a proxy with netsh winhttp show proxy, since the browser’s settings do not apply to the update client.

Renaming SoftwareDistribution and catroot2 is safe. Windows rebuilds both on the next scan; you lose cached downloads and the history list, and nothing that is already installed.

If the scan now runs, you are past it. The next section explains what that cabinet does and why three of the five codes on this page have no published meaning.

Why it happens

A Windows client has no single hard-coded update server. It works out which service applies to it, and the answer arrives as a signed cabinet file that Microsoft’s documentation calls the redirector cab. The client downloads it, parses it and caches it, and everything that happens afterwards depends on having read it successfully. When that step fails the scan does not degrade, it stops, which is why these codes appear immediately rather than partway through.

Microsoft publishes four codes in this range. 0x80245001 is WU_E_REDIRECTOR_LOAD_XML, meaning the redirector XML document could not be loaded into the DOM class. 0x80245002 is WU_E_REDIRECTOR_S_FALSE, the document is missing required information. 0x80245003 is WU_E_REDIRECTOR_ID_SMALLER, the redirector ID in the downloaded cab is lower than the one in the cached cab. 0x80245FFF is the catch-all. That is the whole published list.

The other three codes carried by this article, 0x80245004, 0x80245005 and 0x80245008, are not in it. They appear in neither the current Windows Update error reference nor the archived Windows Update Agent result code list, and they return nothing on Microsoft Learn. They are redirector-range results, so the stage they belong to is not in doubt, but their exact meanings are not published and this page will not invent them. Diagnose them the same way as the documented three: clock, cache, and whatever is between the client and the service.

Something is rewriting the signed download

You have this one if The device sits behind a filtering proxy or an appliance that inspects HTTPS, and other signed content behaves oddly too.

  1. Ask for the update endpoints to be excluded from TLS inspection, not simply permitted. A re-signed response is a different file as far as the client is concerned.
  2. Read the machine context proxy with netsh winhttp show proxy. Microsoft now marks that command deprecated in favour of netsh winhttp show advproxy, and both report the setting the update client actually uses.
  3. Test the same device on a connection outside the filtered network. If the scan works there, the fix belongs on the appliance.

The system clock is wrong

You have this one if The date, time or time zone is visibly out, or the machine loses time across a power cycle.

  1. Correct the time and time zone in Settings, Time and language, Date and time.
  2. Run w32tm /resync from an elevated prompt and confirm the result with w32tm /query /status.
  3. On a domain-joined machine, confirm it is syncing with the domain hierarchy rather than an external source.
  4. Replace the CMOS battery if the machine cannot hold time between boots.

There is no /force parameter on w32tm /resync. The documented parameters are /computer, /nowait, /rediscover and /soft, and an unrecognised switch makes w32tm print its usage block and exit without resyncing anything.

The cached cab is older or damaged

You have this one if 0x80245003 specifically, or a failure that is consistent on one machine while identical machines on the same network scan normally.

  1. Stop wuauserv, bits and cryptsvc.
  2. Rename C:\Windows\SoftwareDistribution and C:\Windows\System32\catroot2.
  3. Start the three services again and run a fresh scan so both are rebuilt from scratch.
  4. Delete the renamed folders once updates are working.

The components that verify signatures are damaged

You have this one if Repair tools report corruption, or other operations that check signatures also fail on this machine.

  1. Run DISM /Online /Cleanup-Image /RestoreHealth and let it finish.
  2. Follow with sfc /scannow and reboot.
  3. If DISM cannot fetch repair files because updates are broken, point it at mounted media of the same build with /Source and /LimitAccess.

Full reference

What Microsoft actually publishes for this range

Code Published name Published description
0x80245001 WU_E_REDIRECTOR_LOAD_XML The redirector XML document could not be loaded into the DOM class
0x80245002 WU_E_REDIRECTOR_S_FALSE The redirector XML document is missing some required information
0x80245003 WU_E_REDIRECTOR_ID_SMALLER The redirector ID in the downloaded redirector cab is less than in the cached cab
0x80245FFF WU_E_REDIRECTOR_UNEXPECTED The redirector failed for a reason not covered by another redirector code

0x80245004, 0x80245005 and 0x80245008 are absent from that table and from the archived Windows Update Agent result codes. If you find a page that states their meanings confidently, check whether it cites a vendor source. In our checks, none does.

Reading 0x80245003 correctly

This one has a specific and useful meaning that is easy to misread. The client compares the redirector ID in the cab it just downloaded against the ID in the cab it already holds, and refuses the new one if it is lower. In practice that means the machine has been handed older service-location data than it already has. The two situations that produce it are a stale cached copy that needs clearing, and something in the path serving a cached older response. Renaming SoftwareDistribution deals with the first; the second is a caching proxy question.

The two proxy configurations, and which one matters

Windows keeps separate proxy settings for interactive users and for services. Your browser uses the per-user settings with your credentials attached. Windows Update runs in the machine context and uses the WinHTTP configuration, with no user, no credentials and no way to answer a prompt. That single difference explains most cases where browsing works and updating does not, and it is why checking the browser proves nothing here.

Command What it does Note
netsh winhttp show proxy Shows the machine-context proxy Microsoft marks this deprecated in favour of show advproxy
netsh winhttp show advproxy The current advanced proxy setting Documented replacement
netsh winhttp reset proxy Clears the machine-context proxy back to DIRECT Safe and reversible, and a good diagnostic
netsh winhttp import proxy source=ie Imports the per-user Internet Options configuration The only documented source

Log evidence worth collecting

  • Run Get-WindowsUpdateLog and read the newest scan. The redirector stage is early and is named clearly in the trace.
  • Compare a working and a failing machine on the same subnet before assuming the network is at fault.
  • On a machine behind an inspecting appliance, check whether the certificate presented for the update endpoints is the vendor’s or the appliance’s.
  • If the device is managed, confirm whether a management platform registered a service that has since been removed. That registration is what the client is trying to resolve.

What this is not

This stage happens before any conversation with an update server, so a reachable WSUS box tells you nothing about it. It is also not component store corruption, despite the fact that DISM and sfc are worth running: they repair the pieces that validate the signature, which is a supporting cause rather than the failure itself. And it is not a licensing problem, so nothing here is fixed by buying anything.

Every code this article covers

Code What it points at Source
0x80245001 WU_E_REDIRECTOR_LOAD_XML. The redirector XML document could not be loaded into the DOM class Microsoft Learn
0x80245003 WU_E_REDIRECTOR_ID_SMALLER. The redirector ID in the downloaded cab is lower than the one in the cached cab Microsoft Learn
0x80245004 A redirector-stage failure. Microsoft’s published redirector table lists only 001, 002, 003 and FFF, so no meaning is available for this value not published by the vendor
0x80245005 A redirector-stage failure with no published description in either the current or the archived Microsoft error lists not published by the vendor
0x80245008 A redirector-stage failure with no published description. Treat it as a blocked, rewritten or stale service-location fetch and work through the same checks not published by the vendor

Confirm the fix worked

  1. A scan in Settings, Windows Update completes rather than stopping immediately.
  2. A new SoftwareDistribution folder exists with a current timestamp.
  3. w32tm /query /status shows the machine synchronised with a sensible source.
  4. One update installs end to end and appears in the update history.

Questions people ask about this

Does this cost anything to fix?

No. Every step uses tools already in Windows. If the cause turns out to be an inspecting proxy, the fix is a configuration change on that device, not a purchase.

Why would the clock matter to Windows Update?

Because the file the client fetches at this stage is signed, and signature validation takes the current time into account. A machine whose clock is badly wrong will refuse content that is entirely valid.

Is renaming SoftwareDistribution safe?

Yes. Windows rebuilds it on the next scan. You lose the cached downloads and the update history view. Nothing already installed is affected.

What do 0x80245004 and 0x80245005 mean?

Microsoft does not say. Its published redirector table lists only 0x80245001, 0x80245002, 0x80245003 and 0x80245FFF, and the archived Windows Update Agent result codes list the same four. They are redirector-stage failures, which tells you where to look, and that is as far as any honest answer goes.

Our WSUS server is reachable, so why does this happen?

Because this step runs before the client talks to any update service. Working out which service applies is a separate fetch, and it can be blocked, cached or rewritten independently of your WSUS server being perfectly healthy.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix 0x80070020: a locked file stops Windows Update replacing system files License Error 0x800F0950 and 0x800F0954: Features on Demand and language packs fail License Error 0xC1420127 and 0xC1900403: the upgrade rolls back every single attempt License Error 0xC1900130 and 0x80190001: the feature update download never finishes
โ† Back to Knowledge Base