Windows 10 22H2, KB5016616, KB5017308, KB5017380, KB5018410, KB5019959, KB5021233 hang on reboot after install

Anonymous
2022-08-11T22:19:21+00:00

I'm trying to update to the latest Win10 update released on 8/8/22. Ever since that update was downloaded the machine hangs

on the required reboot after the install. I have disabled updates until I can find a fix. I've tried to download the update and install

manually but get the same results. Other updates, such as .NET, download and installed fine. Once the machine hangs it has to be rebooted 

2 times to get to the automatic roll back. At least that works for now.  I've run the Update trouble shooter and it doesn't fix anything. 

Windows Update and BITS services are both set to automatic.

There is an error in the event log but I think its from the install abort from a forced shutdown.

Installation Failure: Windows failed to install the following update with error 0x800F0845: 2022-08 Cumulative Update for Windows 10 Version 21H2 for x64-based Systems (KB5016616).

Update 10/5/22: KB-5017308, KB5017380, KB5018410 also FAIL in exactly the same manner as KB-5016616.  Spinning dots on the reboot and the need to do a dual boot auto recovery.  Title has been updated.

Any help would be appreciated.

Windows for home | Windows 10 | Install and upgrade

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2022-12-26T20:47:58+00:00

For me, the following solved the Problem:

Delete the Value data (all bytes) of

HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\NL$KM\CurrVal(Default)

and

HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\NL$KM\OldVal(Default)

One reboot and CurrVal(Default) should be filled again.

If you are not domain-joined, i would not expect any problems.

I'm not giving directions on how to access and delete the value data because i want skilled people who know what they are doing to test my solution.

Was this answer helpful?

20+ people found this answer helpful.
0 comments No comments

319 additional answers

Sort by: Most helpful
  1. Anonymous
    2023-03-17T21:08:20+00:00

    Finally they fixed it.

    They changed their code to accept the original NL$KM values again.

    But they ALSO released the code that broke the whole update mechanism.

    So many people were affected by this issue and no word and no solution for 7 months ?

    No possibility to patch security issues for such a long time.

    I have no praise for this achievement.

    Spot on, info001, just as your original. The real issue is that there seems no way of reporting such direct to MS Just start a thread like this and hope that someone in MS might read it. But why would they? Or have I missed something?

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2023-03-17T20:44:19+00:00

    Finally they fixed it.

    They changed their code to accept the original NL$KM values again.

    But they ALSO released the code that broke the whole update mechanism.

    So many people were affected by this issue and no word and no solution for 7 months ?

    No possibility to patch security issues for such a long time.

    I have no praise for this achievement.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2023-01-07T22:12:47+00:00

    It is actually much simpler than PSTools. PSEexec etc.

    You need to seethe structure under "SECURITY" as per glzbsg's post 30/12/22, and be able to change it

    But it will by default not show there.

    Just follow this, in native W10, no 3rd party software needed.

    Assuming you are logged in as an admistrator:

    (That will normally be the case for the primary user of a personal machine.)

    Run Regedit

    Allow changes? "Yes"

    Click on "SECURITY" folder

    No subfolders showing?

    OK, Right click, Choose "Permissions"

    Select "Administrators"

    Tick Box "Full Control / Allow"

    Close Regedit

    Run Regedit again

    Now "Security" folders sre visble

    Select "Policy" / "Secrets" / "NLSKM"

    Now "Currval" & "OldVal" are visible.

    Delete the keys in each as per info001's instructions insructions.

    Exit Regedit

    Reboot

    Done?

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2022-12-14T16:37:39+00:00

    MS volunteer moderators do watch this thread. So MS must know about the problem and basically told us to go pound salt. 

    We've received tips from one MS person early on then another rehashed what we've been doing for 5 months.  Interestingly enough, he didn't like us pointing the rehash out, blamed Google Search for the problem and then deleted our and his posts regarding it. If you are going to go through the risk and work of reinstalling a clean OS then I suggest moving to a more robust system like iOS or Linux and dump Windows.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments