Fix it now
Before any scan happens, Windows Update downloads and parses a small signed cabinet that tells it which update service applies to this device. Microsoft publishes 0x80245001 as the redirector XML failing to load, and 0x80245003 as a downloaded cab whose redirector ID is lower than the cached one. Clear the cache, fix the clock, and stop anything rewriting the download.
w32tm /resync
net stop wuauserv
net stop bits
net stop cryptsvc
ren C:\Windows\SoftwareDistribution SoftwareDistribution.old
ren C:\Windows\System32\catroot2 catroot2.old
net start cryptsvc
net start bits
net start wuauserv
- Check the result of the time sync with
w32tm /query /status. The cab is signed, and a machine whose clock is badly wrong will reject content that is perfectly valid. - Scan again from Settings, Windows Update and see whether the code changes. A different code after the cache reset means you have moved past this stage.
- If it persists, look at what sits between the device and Microsoft. Ask for the update endpoints to be excluded from TLS inspection rather than merely allowed through.
- Confirm what the machine account itself uses for a proxy with
netsh winhttp show proxy, since the browser’s settings do not apply to the update client.
Renaming SoftwareDistribution and catroot2 is safe. Windows rebuilds both on the next scan; you lose cached downloads and the history list, and nothing that is already installed.
If the scan now runs, you are past it. The next section explains what that cabinet does and why three of the five codes on this page have no published meaning.
Why it happens
A Windows client has no single hard-coded update server. It works out which service applies to it, and the answer arrives as a signed cabinet file that Microsoft’s documentation calls the redirector cab. The client downloads it, parses it and caches it, and everything that happens afterwards depends on having read it successfully. When that step fails the scan does not degrade, it stops, which is why these codes appear immediately rather than partway through.
Microsoft publishes four codes in this range. 0x80245001 is WU_E_REDIRECTOR_LOAD_XML, meaning the redirector XML document could not be loaded into the DOM class. 0x80245002 is WU_E_REDIRECTOR_S_FALSE, the document is missing required information. 0x80245003 is WU_E_REDIRECTOR_ID_SMALLER, the redirector ID in the downloaded cab is lower than the one in the cached cab. 0x80245FFF is the catch-all. That is the whole published list.
The other three codes carried by this article, 0x80245004, 0x80245005 and 0x80245008, are not in it. They appear in neither the current Windows Update error reference nor the archived Windows Update Agent result code list, and they return nothing on Microsoft Learn. They are redirector-range results, so the stage they belong to is not in doubt, but their exact meanings are not published and this page will not invent them. Diagnose them the same way as the documented three: clock, cache, and whatever is between the client and the service.
Something is rewriting the signed download
You have this one if The device sits behind a filtering proxy or an appliance that inspects HTTPS, and other signed content behaves oddly too.
- Ask for the update endpoints to be excluded from TLS inspection, not simply permitted. A re-signed response is a different file as far as the client is concerned.
- Read the machine context proxy with
netsh winhttp show proxy. Microsoft now marks that command deprecated in favour ofnetsh winhttp show advproxy, and both report the setting the update client actually uses. - Test the same device on a connection outside the filtered network. If the scan works there, the fix belongs on the appliance.
The system clock is wrong
You have this one if The date, time or time zone is visibly out, or the machine loses time across a power cycle.
- Correct the time and time zone in Settings, Time and language, Date and time.
- Run
w32tm /resyncfrom an elevated prompt and confirm the result withw32tm /query /status. - On a domain-joined machine, confirm it is syncing with the domain hierarchy rather than an external source.
- Replace the CMOS battery if the machine cannot hold time between boots.
There is no /force parameter on w32tm /resync. The documented parameters are /computer, /nowait, /rediscover and /soft, and an unrecognised switch makes w32tm print its usage block and exit without resyncing anything.
The cached cab is older or damaged
You have this one if 0x80245003 specifically, or a failure that is consistent on one machine while identical machines on the same network scan normally.
- Stop
wuauserv,bitsandcryptsvc. - Rename
C:\Windows\SoftwareDistributionandC:\Windows\System32\catroot2. - Start the three services again and run a fresh scan so both are rebuilt from scratch.
- Delete the renamed folders once updates are working.
The components that verify signatures are damaged
You have this one if Repair tools report corruption, or other operations that check signatures also fail on this machine.
- Run
DISM /Online /Cleanup-Image /RestoreHealthand let it finish. - Follow with
sfc /scannowand reboot. - If DISM cannot fetch repair files because updates are broken, point it at mounted media of the same build with
/Sourceand/LimitAccess.
Full reference
What Microsoft actually publishes for this range
| Code | Published name | Published description |
|---|---|---|
0x80245001 |
WU_E_REDIRECTOR_LOAD_XML | The redirector XML document could not be loaded into the DOM class |
0x80245002 |
WU_E_REDIRECTOR_S_FALSE | The redirector XML document is missing some required information |
0x80245003 |
WU_E_REDIRECTOR_ID_SMALLER | The redirector ID in the downloaded redirector cab is less than in the cached cab |
0x80245FFF |
WU_E_REDIRECTOR_UNEXPECTED | The redirector failed for a reason not covered by another redirector code |
0x80245004, 0x80245005 and 0x80245008 are absent from that table and from the archived Windows Update Agent result codes. If you find a page that states their meanings confidently, check whether it cites a vendor source. In our checks, none does.
Reading 0x80245003 correctly
This one has a specific and useful meaning that is easy to misread. The client compares the redirector ID in the cab it just downloaded against the ID in the cab it already holds, and refuses the new one if it is lower. In practice that means the machine has been handed older service-location data than it already has. The two situations that produce it are a stale cached copy that needs clearing, and something in the path serving a cached older response. Renaming SoftwareDistribution deals with the first; the second is a caching proxy question.
The two proxy configurations, and which one matters
Windows keeps separate proxy settings for interactive users and for services. Your browser uses the per-user settings with your credentials attached. Windows Update runs in the machine context and uses the WinHTTP configuration, with no user, no credentials and no way to answer a prompt. That single difference explains most cases where browsing works and updating does not, and it is why checking the browser proves nothing here.
| Command | What it does | Note |
|---|---|---|
netsh winhttp show proxy |
Shows the machine-context proxy | Microsoft marks this deprecated in favour of show advproxy |
netsh winhttp show advproxy |
The current advanced proxy setting | Documented replacement |
netsh winhttp reset proxy |
Clears the machine-context proxy back to DIRECT | Safe and reversible, and a good diagnostic |
netsh winhttp import proxy source=ie |
Imports the per-user Internet Options configuration | The only documented source |
Log evidence worth collecting
- Run
Get-WindowsUpdateLogand read the newest scan. The redirector stage is early and is named clearly in the trace. - Compare a working and a failing machine on the same subnet before assuming the network is at fault.
- On a machine behind an inspecting appliance, check whether the certificate presented for the update endpoints is the vendor’s or the appliance’s.
- If the device is managed, confirm whether a management platform registered a service that has since been removed. That registration is what the client is trying to resolve.
What this is not
This stage happens before any conversation with an update server, so a reachable WSUS box tells you nothing about it. It is also not component store corruption, despite the fact that DISM and sfc are worth running: they repair the pieces that validate the signature, which is a supporting cause rather than the failure itself. And it is not a licensing problem, so nothing here is fixed by buying anything.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x80245001 |
WU_E_REDIRECTOR_LOAD_XML. The redirector XML document could not be loaded into the DOM class | Microsoft Learn |
0x80245003 |
WU_E_REDIRECTOR_ID_SMALLER. The redirector ID in the downloaded cab is lower than the one in the cached cab | Microsoft Learn |
0x80245004 |
A redirector-stage failure. Microsoft’s published redirector table lists only 001, 002, 003 and FFF, so no meaning is available for this value | not published by the vendor |
0x80245005 |
A redirector-stage failure with no published description in either the current or the archived Microsoft error lists | not published by the vendor |
0x80245008 |
A redirector-stage failure with no published description. Treat it as a blocked, rewritten or stale service-location fetch and work through the same checks | not published by the vendor |
Confirm the fix worked
- A scan in Settings, Windows Update completes rather than stopping immediately.
- A new
SoftwareDistributionfolder exists with a current timestamp. w32tm /query /statusshows the machine synchronised with a sensible source.- One update installs end to end and appears in the update history.
Questions people ask about this
Does this cost anything to fix?
No. Every step uses tools already in Windows. If the cause turns out to be an inspecting proxy, the fix is a configuration change on that device, not a purchase.
Why would the clock matter to Windows Update?
Because the file the client fetches at this stage is signed, and signature validation takes the current time into account. A machine whose clock is badly wrong will refuse content that is entirely valid.
Is renaming SoftwareDistribution safe?
Yes. Windows rebuilds it on the next scan. You lose the cached downloads and the update history view. Nothing already installed is affected.
What do 0x80245004 and 0x80245005 mean?
Microsoft does not say. Its published redirector table lists only 0x80245001, 0x80245002, 0x80245003 and 0x80245FFF, and the archived Windows Update Agent result codes list the same four. They are redirector-stage failures, which tells you where to look, and that is as far as any honest answer goes.
Our WSUS server is reachable, so why does this happen?
Because this step runs before the client talks to any update service. Working out which service applies is a separate fetch, and it can be blocked, cached or rewritten independently of your WSUS server being perfectly healthy.
