Fix it now
Every number here belongs to WinINet, the Windows internet layer the installer uses to fetch its files, and Microsoft publishes what each one means. They describe a connection that failed, not a product that is broken, and none of them is a licensing fault.
netsh winhttp show proxy
ipconfig /flushdns
w32tm /resync
- Retry the download once. A single failed transfer on a busy connection is not worth investigating.
- Open any website on the same machine to confirm the connection works at all, then check the date and time zone, because a wrong clock breaks secure connections outright.
- Read the number. A name-not-resolved error is DNS, a cannot-connect error is the transport or a firewall, a timeout is a slow or silently dropping path, and an invalid server response means something in the middle answered instead of the server.
- Disconnect any VPN, pause download managers, and stop a third-party firewall briefly while you retry.
- If you are on a managed or filtered network, try a phone hotspot. Completing there proves the fault is that network rather than your PC.
These are generic Windows networking errors, which is why searching for them returns results from completely unrelated software. The number tells you the layer; it tells you nothing about McAfee.
If setup completes, you are done. If it keeps failing at the same layer, the next section maps each code to the thing that produces it.
Why it happens
McAfee’s consumer installer is a small program that fetches the real payload while it runs. To do that it uses the Windows internet API, and when a request fails, that API’s error number is what the installer has to report. The five-digit codes on this page come straight from WinINet, and Microsoft publishes the text for every one of them.
Read together they narrow the problem down neatly. “The server name could not be resolved” is DNS. “The attempt to connect to the server failed” is the transport or a firewall. “The request has timed out” is a slow or saturated path, or one that drops packets silently. “The server response could not be parsed” is the one people find hardest to place: something answered, and what came back was not a response the client could read, which is the classic signature of a captive portal, a filtering proxy or a TLS-inspecting appliance rewriting the traffic.
The fifth one is different in kind. “The requested operation cannot be carried out because the handle supplied is not in the correct state” is the client’s own bookkeeping, not the network. In practice it turns up after one of the other four has already happened and the installer has carried on with a handle it should have discarded – so treat it as a symptom of an earlier failure rather than as a separate fault to chase.
The practical consequence is that fixing this rarely involves McAfee at all. You are fixing the path between the machine and the internet, and once that is sound the installer completes on the first attempt.
A proxy or inspecting firewall is rewriting the traffic
You have this one if Failure is immediate and consistent on a managed network, and other software updaters on the same machine also struggle. The code is usually the one about an unparseable server response.
- Confirm the proxy configuration with
netsh winhttp show proxyand in the LAN settings dialog under Internet Options. - Where TLS inspection is in use, ask for McAfee’s download endpoints to be excluded. A re-signed certificate does not validate against what the client expects.
- On an authenticating proxy, ask whether the installer can be given an exception or run from an unfiltered segment.
- Retest from a hotspot to prove the diagnosis before requesting any firewall change.
DNS is not resolving the download host
You have this one if The failure is immediate and the code is the name-not-resolved one; other sites on the same machine are also intermittent.
- Run
ipconfig /flushdnsfrom an elevated Command Prompt. - Check whether a filtering DNS service or a router-level parental control is blocking the domain.
- Test with a different DNS server temporarily to confirm, then decide whether the block was deliberate.
- Check the hosts file for stale entries left by an optimiser or an older security product.
The session drops part way through the transfer
You have this one if The download reaches a different point each time before failing, on a connection that is otherwise usable.
- Retry on a wired connection rather than wireless, and stop other large transfers while it runs.
- Disconnect any VPN. A kill switch or a reconnect mid-transfer ends the session cleanly from the installer’s point of view.
- Check free disk space and that
%temp%is writable. - Ask McAfee support whether a full offline package is available for your product, so the transfer stops being part of setup.
The system clock is wrong, so secure connections fail
You have this one if The machine has a visibly wrong date, often after a flat CMOS battery or a restored virtual machine.
- Open Settings, Time & language, Date & time, turn on automatic time and time zone, and choose Sync now.
- Run
w32tm /resyncfrom an elevated prompt. - Replace the motherboard battery if the clock resets on every cold boot.
- Retry the installer once the date is right.
The documented parameters of w32tm /resync are /computer, /nowait, /rediscover and /soft. /force is not one of them and the command rejects it.
A firewall is dropping the connection silently
You have this one if The failure is a timeout rather than a refusal – nothing answers, and the wait is long.
- Stop a third-party firewall briefly as a diagnostic, on a network you trust, and retry.
- If that lets the download through, write a rule for the installer rather than leaving the firewall off.
- On a corporate network, ask for the download endpoints to be permitted rather than working around the policy.
Full reference
Microsoft’s published text for each code
| Code | Constant | Microsoft’s published description |
|---|---|---|
12152 |
ERROR_HTTP_INVALID_SERVER_RESPONSE | The server response could not be parsed |
12007 |
ERROR_INTERNET_NAME_NOT_RESOLVED | The server name could not be resolved |
12029 |
ERROR_INTERNET_CANNOT_CONNECT | The attempt to connect to the server failed |
12002 |
ERROR_INTERNET_TIMEOUT | The request has timed out |
12019 |
ERROR_INTERNET_INCORRECT_HANDLE_STATE | The requested operation cannot be carried out because the handle supplied is not in the correct state |
Mapping symptom to layer
| Symptom | Layer at fault | First check |
|---|---|---|
| Fails instantly, host name cannot be found | DNS | ipconfig /flushdns, then router-level filtering |
| Fails after a pause with a timeout | Slow path, or a silently dropping firewall | Try a hotspot; stop a third-party firewall as a test |
| Fails part way through a large download | Session dropped in transit | Wired connection, VPN off, check disk space |
| Fails immediately with an unparseable response | A proxy, captive portal or inspecting appliance | netsh winhttp show proxy, then TLS inspection policy |
| Works on a hotspot, fails at the office | That network’s filtering rules | Ask for the endpoints to be permitted |
Why a handle-state error is not its own problem
12019 is worth a paragraph because it sends people down the wrong path. Microsoft’s text is about a handle supplied in the wrong state – an internal sequencing condition, not a network event. On a failing download it generally appears after one of the other four codes has already occurred. Fix the layer that produced the first error and this one goes with it; there is nothing to configure that addresses it directly.
Checking a proxy properly
- Run
netsh winhttp show proxyin an elevated Command Prompt. This reports the WinHTTP proxy, which is separate from the browser’s. - Open Internet Options, Connections, LAN settings, and read what is configured there. This is the one most installers follow.
- Check for a proxy auto-config script as well as a manual proxy – a PAC file can send some hosts through an appliance and not others.
- Where a corporate appliance is in the path, ask whether it performs TLS inspection. That single fact explains most unparseable-response failures.
When the network is not yours to fix
Managed networks inspect and filter traffic by design. An installer that expects an unmodified secure connection sees the inspection as an invalid response, and no client-side setting changes that. If the machine belongs to an employer, the installation has to go through whoever manages it – and that is a policy conversation rather than a troubleshooting one. Confirm the diagnosis on a hotspot first so you can say precisely what needs permitting.
Before you retry again
- Download a fresh copy of the installer rather than reusing a file that already failed part way.
- Confirm
%temp%exists, is writable by your account, and has room. - Confirm the system volume has well over the size of the package free.
- Stop anything that resumes downloads on your behalf, including download managers and sync clients.
- Do not disable the firewall and leave it disabled. Use it as a five-minute diagnostic and then write a rule.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
12152 |
ERROR_HTTP_INVALID_SERVER_RESPONSE – the server response could not be parsed | Microsoft Learn |
12007 |
ERROR_INTERNET_NAME_NOT_RESOLVED – the server name could not be resolved | Microsoft Learn |
12029 |
ERROR_INTERNET_CANNOT_CONNECT – the attempt to connect to the server failed | Microsoft Learn |
12002 |
ERROR_INTERNET_TIMEOUT – the request has timed out | Microsoft Learn |
12019 |
ERROR_INTERNET_INCORRECT_HANDLE_STATE – the operation cannot be carried out because the handle supplied is not in the correct state | Microsoft Learn |
Confirm the fix worked
- The installer runs to completion without a network error.
- The McAfee app opens and reports protection as on.
- Updates complete on the same connection that failed before.
netsh winhttp show proxyreports what you expect it to report.- Repeat the update a day later to confirm the network fix was permanent rather than a lucky window.
Questions people ask about this
Do I need to buy anything to solve this?
No. These are Windows network errors raised during a download. Your subscription, if you have one, is untouched, and the fix is free.
Why do these numbers turn up for unrelated software?
Because they are not McAfee’s. They belong to WinINet, the Windows internet API, and any application that uses it reports the same numbers for the same conditions.
Should I turn off my firewall to install?
Only briefly, as a diagnostic, and only on a network you trust. If disabling it lets the download through, write a rule for the installer rather than leaving the firewall off.
Why does it fail at work but not at home?
Managed networks inspect and filter traffic. An installer that expects an unmodified secure connection sees inspection as an unparseable response – which is exactly what 12152 says. That is a policy question for whoever runs the network.
Is there a way to install without downloading during setup?
Ask McAfee support whether a full offline package exists for your product. It moves the transfer out of the installer so you can retry the download on its own terms.
