Fix it now
0x80070643 is the HRESULT form of Win32 1603, ERROR_INSTALL_FAILURE – a fatal error during installation, with no component-specific meaning at all. That is why it turns up against unrelated updates, so the first job is to read which item actually failed rather than to start repairing Defender.
Get-MpComputerStatus | Select-Object AMServiceEnabled,AntivirusSignatureVersion,AntivirusSignatureLastUpdated,AMEngineVersion,AMProductVersion
Update-MpSignature
- Open Settings, Windows Update, Update history and read the name of the item that failed. A security intelligence update and a Windows Recovery Environment update are different problems that share this code.
- If it is the definitions, run
Update-MpSignaturein elevated PowerShell; the error it returns is more use than the one in the history list. - If that fails, restore the definitions and pull a fresh set from an elevated Command Prompt:
"%ProgramFiles%\Windows Defender\MpCmdRun.exe" -RemoveDefinitions -Allthen"%ProgramFiles%\Windows Defender\MpCmdRun.exe" -SignatureUpdate. - If the failing item is the recovery environment, check the System log for event 4502, “Windows Recovery Environment servicing failed”, with ErrorPhase 2 – that is the recovery partition being too small.
- Run
reagentc /infoand note whether WinRE is enabled and which partition holds it. - Confirm the outcome with
Get-MpComputerStatusand read the signature version and last-updated time.
MpCmdRun -RemoveDefinitions -All restores the installed security intelligence to a previous backup copy or to the original default set. Run the update immediately afterwards rather than leaving the machine on an old set.
If the signature timestamp is today and Windows Security reports itself up to date, you are done. If not, the next section separates the two cases.
Why it happens
0x80070643 carries no diagnostic information. Microsoft publishes 1603 as ERROR_INSTALL_FAILURE, a fatal error during installation, and Windows Update shows the HRESULT form of it for anything that dies inside the servicing path. Everything useful therefore comes from establishing which update produced it, and that is a thirty-second job in Update history that most people skip.
On the Defender side, security intelligence arrives as a small package that the Defender platform applies to its local store. If that store is damaged, or the platform build is broken, or Defender has been put into disabled mode by another antivirus registering itself, the apply step fails. The companion code worth recognising is 0x8007139F, which is the HRESULT form of Win32 5023, ERROR_INVALID_STATE – the resource is not in the correct state to perform the requested operation. That is what a disabled Defender being asked to update looks like.
The recovery environment case has nothing to do with antivirus. WinRE lives on its own small partition and servicing it needs free space there to stage a replacement image. Many factory layouts leave almost none, so the update fails, Windows Update retries it indefinitely, and it sits in the history list looking like a security problem. The signal that tells you this is your case is specific: System event 4502, Windows Recovery Environment servicing failed, with ErrorPhase 2.
0x80073B01 sometimes appears alongside, and it is worth being honest about it. Microsoft does not publish it as a Microsoft Defender Antivirus code. Decoded as an HRESULT it is Win32 15105, ERROR_MUI_FILE_NOT_LOADED, a resource-loader error, which does not support the confident readings you will find elsewhere. Note it, do not build on it.
The definition store needs restoring and refreshing
You have this one if The definition update fails repeatedly and the signature timestamp in Get-MpComputerStatus has not moved for days.
- From an elevated Command Prompt, run
"%ProgramFiles%\Windows Defender\MpCmdRun.exe" -RemoveDefinitions -All. - Immediately follow it with
"%ProgramFiles%\Windows Defender\MpCmdRun.exe" -SignatureUpdate. - If that returns an error, run
Update-MpSignaturein elevated PowerShell to see whether the failure is in the download or the apply. - Restart and check
Get-MpComputerStatusagain; the signature timestamp should be current.
Between the restore and the new set arriving, the machine is on an older signature version. Run the two commands back to back, not hours apart.
Defender is in disabled mode, so nothing can be applied
You have this one if 0x8007139F appears with the failure, or Get-MpComputerStatus reports the antimalware service as not enabled.
- Open Windows Security, Settings, Manage providers and see which product Windows currently regards as the active antivirus.
- If a non-Microsoft antivirus is registered, Defender being disabled is documented behaviour on Windows client and the definition failures are a side effect rather than a fault.
- If a product you already removed is still listed, run its vendor’s removal tool to clear the registration.
- Restart, confirm Defender reports itself as on, and retry the update.
The failing item is the recovery environment update
You have this one if Update history names a recovery environment update, and the System log carries event 4502 with ErrorPhase 2, while Defender’s own signature date is current.
- Run
reagentc /infofrom an elevated Command Prompt and note whether WinRE is enabled and which partition holds it. - Check the free space on that recovery partition in Disk Management.
- Follow Microsoft’s published procedure, which disables WinRE, shrinks the OS partition by 250 MB, deletes the existing recovery partition, creates a new one and re-enables WinRE.
- If creation fails or you decide not to proceed, run
reagentc /enableto put WinRE back before doing anything else.
Nothing about this affects your antivirus. If your signature date is current, your protection is current, whatever the update history says.
Repartitioning is the one step here that can cost you data. Take a full backup first, confirm you have your BitLocker recovery key if the drive is encrypted, and follow Microsoft’s published procedure rather than improvising with diskpart on a machine you cannot afford to rebuild.
The Windows Update components are damaged
You have this one if Other updates fail too, not only this one, and retries never behave differently.
- In an elevated Command Prompt, run
sfc /scannow, thenDISM /Online /Cleanup-Image /RestoreHealth, and restart. - Run the Windows Update troubleshooter from Settings, System, Troubleshoot, Other troubleshooters.
- Retry the update and read the new result rather than assuming the old code still applies.
Full reference
Telling the two cases apart
| What you observe | Which problem it is |
|---|---|
| Update history names a security intelligence update | The definition package is failing to apply |
| Update history names a recovery environment update | A WinRE servicing failure, unrelated to your protection |
| System event 4502 with ErrorPhase 2 | The recovery partition is too small to stage the new image |
Update-MpSignature succeeds but the history entry still shows failed |
A stale history entry; trust the signature timestamp |
| 0x8007139F alongside it | Defender is not in a state that permits the operation |
Get-MpComputerStatus shows old signature and platform versions |
The platform itself is stuck, not just the definitions |
MpCmdRun, and where it lives
Microsoft documents two locations for MpCmdRun.exe: C:\Program Files\Windows Defender, and the platform folder at C:\ProgramData\Microsoft\Windows Defender\Platform\<version>, with the platform copy being the recommended one because it is the current build. If a command from the Program Files copy behaves oddly on a machine whose platform has been updated many times, try the platform copy.
| Command | What Microsoft documents it as doing |
|---|---|
-RemoveDefinitions -All |
Restores the installed security intelligence to a previous backup copy or to the original default set |
-RemoveDefinitions -Engine |
Restores the previously installed engine |
-RemoveDefinitions -DynamicSignatures |
Removes only dynamically downloaded security intelligence |
-SignatureUpdate |
Checks for new security intelligence updates |
-SignatureUpdate -MMPC |
Downloads updates directly from the Microsoft Malware Protection Center |
-SignatureUpdate -UNC <path> |
Downloads updates directly from a UNC file share |
-GetFiles |
Collects logs into MpSupportFiles.cab for a support case |
The events to read, and where
Defender’s own log is Applications and Services Logs, Microsoft, Windows, Windows Defender, Operational. Two entries matter here.
- Event 2001, MALWAREPROTECTION_SIGNATURE_UPDATE_FAILED – the security intelligence update failed. It carries the update source, the update stage (Search, Download or Install), the error code and its description. The stage is the useful part: a failure at Download is a network problem and a failure at Install is not.
- Event 2003, MALWAREPROTECTION_ENGINE_UPDATE_FAILED – the antimalware engine update failed, which is a different package from the signatures and can fail on its own.
- For the recovery-environment case, look in Windows Logs, System for event 4502 rather than in the Defender log at all.
How exposed the machine actually is
Less than the red banner suggests, and more than nothing. Cloud-delivered protection continues to work while the machine is online, so new threats are still checked against Microsoft’s service. What ages is the local set, and the gap widens daily. Treat a machine that has been failing for a week as urgent and one that failed this morning as routine.
When to stop and collect evidence instead
- Run
"%ProgramFiles%\Windows Defender\MpCmdRun.exe" -GetFilesto gather the Defender logs into a cab file. - Note the update stage from event 2001, because it tells a support engineer whether to look at the network or the platform.
- Note the platform, engine and signature versions from Get-MpComputerStatus.
- Note whether any non-Microsoft antivirus is or has been installed, and whether its registration is still present.
- Take that set to support rather than reinstalling Windows, which is where people go far too early with this code.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x80070643 |
The HRESULT form of Win32 1603, ERROR_INSTALL_FAILURE: a fatal error occurred during installation. It carries no component-specific meaning, which is why it appears against unrelated updates | Microsoft Learn |
0x80073B01 |
Not published by Microsoft as a Defender code. Decoded as an HRESULT it is Win32 15105, ERROR_MUI_FILE_NOT_LOADED, a resource-loader error; treat it as unexplained rather than as evidence of damaged Defender components | not published by the vendor |
0x8007139F |
The HRESULT form of Win32 5023, ERROR_INVALID_STATE: the resource is not in the correct state to perform the requested operation | Microsoft Learn |
Event ID 2001 |
MALWAREPROTECTION_SIGNATURE_UPDATE_FAILED: the security intelligence update failed. The event carries the update source, the stage – Search, Download or Install – and the error code | Microsoft Learn |
Event ID 2003 |
MALWAREPROTECTION_ENGINE_UPDATE_FAILED: the antimalware engine update failed, as distinct from a signature update | Microsoft Learn |
Confirm the fix worked
Get-MpComputerStatusshows a signature timestamp from today and the antimalware service enabled.- Windows Security reports protection as up to date rather than showing a warning.
- The Defender operational log records a successful update rather than repeating 2001 or 2003.
- Windows Update history shows the previously failing item as installed, or shows nothing pending.
- Restart and confirm the next scheduled update also succeeds, rather than only the one you forced.
Questions people ask about this
Do I have to buy anything to fix this?
No. Microsoft Defender is part of Windows and its definitions cost nothing however many times a day it downloads them. Every step here uses tools already on the machine. If a site is offering to sell you a fix for 0x80070643, close it.
How exposed am I while updates are failing?
Less than you might fear, but not comfortable. Cloud-delivered protection still works while the machine is online. What ages is the local signature set, and that gap widens every day.
Windows Update keeps retrying the same failed item. Can I stop it?
You can hide an individual update, but only once you know it is the recovery environment item and not a definition update. A hidden security intelligence update is a genuinely bad outcome.
What does 0x80070643 actually mean?
Win32 1603, ERROR_INSTALL_FAILURE – a fatal error during installation. That is the whole published meaning. It says nothing about Defender, which is why the same code appears against .NET, Exchange cumulative updates and the recovery environment.
Should I reinstall Windows over this?
Almost never. Defender’s platform, its definitions and the recovery environment can each be repaired independently, and the recovery-partition case has a published procedure. Exhaust those first.
