I use the script presented here:
I just replace the filter with
Type='Software'
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I use the windows update api to check which cabs are installed on the machine:
https://learn.microsoft.com/en-us/windows/win32/wua_sdk/using-the-windows-update-agent-api
On Windows 11 the scan sends incorrect information and duplicate cabs.
What I was able to observe is that for a 24h2, the API also sees the cumulative updates of the 23h3 and the 22h2 (the cab numbers are indicated but not their update id.).
In addition, the API indicates that the cab is installed, which is false since it has just been detected.
Is the 24h2 cab considered not installed. Which is true
Looks like there is a detectoid problem.
This is problematic because if we base ourselves on the kbids, Windows makes us believe that the cab is properly installed... Finally we have two contradictory results.
I use the script presented here:
I just replace the filter with
Type='Software'
I can confirm that this bug is still present in Windows 11 25H2. The API keeps reporting older cumulative KBs as “installed” even when they are not. It’s really frustrating to see that nothing has changed after all this time.
I just saw that the problem is also visible on a wsus server (which seems logical). I have the impression that the 24h2 windows update engine is completely crap.
Is there still someone at the helm at Microsoft to take things in hand?
Hello,
If this is indeed a detectoid issue in the WUA API, it’s important to report it to Microsoft:
File Feedback:
Use the Feedback Hub app in Windows 11 to report the issue.
Provide detailed steps to reproduce the issue, including the WUA API query and the observed results.
Contact Microsoft Support:
Provide them with the following information:
Windows version (24H2).
WUA API query details.
Logs from Get-WindowsUpdateLog or dism /get-packages.
Best Regards,
Hania Lian
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.
I think that you just need to look at the IsInstalled peoperty.
I used the PowerShell version and made a slight change to the output.
$UpdateSession = New-Object -ComObject Microsoft.Update.Session
$UpdateServiceManager = New-Object -ComObject Microsoft.Update.ServiceManager
$UpdateService = $UpdateServiceManager.AddScanPackageService("Offline Sync Service", "c:\temp\wsusscn2.cab")
$UpdateSearcher = $UpdateSession.CreateUpdateSearcher()
Write-Host "Searching for updates..."
$UpdateSearcher.ServerSelection = 3 # ssOthers
$UpdateSearcher.ServiceID = [string] $UpdateService.ServiceID
$SearchResult = $UpdateSearcher.Search("Type='Software'") #IsInstalled=0")
$Updates = $SearchResult.Updates
If ($SearchResult.Updates.Count -eq 0) {
Write-Host "There are no applicable updates."
return
}
Write-Host "List of applicable items on the machine when using wssuscan.cab:"
For ($i = 0; $i -lt $SearchResult.Updates.Count; $i++) {
$update = $SearchResult.Updates.Item($i)
#Write-Host ($i + 1) "> " $update.Title
[PSCustomObject]@{
IsInstalled = $update.IsInstalled
Type = $update.Type
Title = $update.Title
}
}
On my Win11 laptop it reports this.
I have a Win10 VM that I don't use very often. It reports that it is missing some updates.
....