Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To see the Windows Update events represented in Settings, query the Windows Update Agent with PowerShell; from Command Prompt, you can run the same query through powershell.exe. Use Get-HotFix when you only need to check servicing hotfixes reported through CBS, not as a complete update history.

The Settings page is the simplest way to review update activity. For command-line checks, the methods differ in what they report, so choose the one that matches your need.

Check Windows Update history in Settings

If you only need to see recent update activity, the graphical method is the quickest. Microsoft documents these paths in its Windows Update FAQ.

Windows 11

  1. Open Start > Settings.
  2. Select Windows Update.
  3. Choose Update history.

The page lists updates and the dates on which Windows installed them. To remove an update, select Uninstall updates, choose the update, and select Uninstall. Some updates cannot be removed.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Windows 10

  1. Open Start > Settings.
  2. Select Update & Security.
  3. Open Windows Update.
  4. Select View update history.

To remove an eligible update, select Uninstall updates, choose it in the list, and select Uninstall.

Support note: Windows 10 support ended on October 14, 2025. Its final feature update was version 22H2. Microsoft no longer provides free Windows Update software updates, technical assistance, or security fixes for Windows 10 after that date, as described in its Windows update guidance.

Use PowerShell to list installed KBs

Open PowerShell and run:

Get-HotFix

This returns hotfixes reported by the local computer, commonly including the KB number, description, installation date, and the account that installed the update. Get-HotFix uses the Win32_QuickFixEngineering WMI class; see Microsoft’s Get-HotFix documentation.

To display the most recently dated result:

(Get-HotFix | Sort-Object -Property InstalledOn)[-1]

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To check for a specific KB, replace the example number with the one you need:

Get-HotFix -Id KB1234567

If the KB is present, PowerShell returns its details. If it is not present, the command normally returns no result.

You can check several exact KB IDs in one command:

Get-HotFix -Id KB4012212,KB4012215,KB4015549

The -Id parameter accepts a string array, but it does not accept wildcards. For example, KB123* is not a valid way to search for related KBs.

Query another computer

With appropriate access to the remote computer, run:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
2-Pack Window/Door Alarm When Opened for Kids/Dementia Safety/Home Security
  • [Door / Window Alarm] Ensures home security and kids' safety by alerting on door/window open, preventing intrusions, and keeping your family and property secure, even during power outages.
  • [Adjustable 90dB/120dB Alarm] Customize your security with two volume settings: 90dB for discreet alerts, and 120dB for powerful deterrence and immediate attention.
  • [600FT Remote Control] The door sensor alarm is equipped with remote control functionality for easy operation, with a maximum range of up to 600 feet, allowing you to manage and control the security system effortlessly from anywhere.
  • [Wide Usage] The door/window open alarms is suitable for various residential homes, apartments, small commercial spaces, pool sliding door, front/back door, sliding glass door, and areas requiring kid/Elderly safety, making it an ideal choice for enhancing family and property security.
  • [Easy to USE] Easy installation with magnetic sensor design and durable 3M adhesive, requiring no complex tools. Powered by 2 AAA (not included) batteries for long-lasting stable operation.

Get-HotFix -ComputerName COMPUTERNAME

For alternate credentials:

Get-HotFix -ComputerName COMPUTERNAME -Credential (Get-Credential)

The -ComputerName query uses the underlying WMI mechanism. It does not require PowerShell remoting to be enabled, although firewall rules, permissions, and the remote computer’s WMI configuration can still prevent the query from working.

Important: Get-HotFix is not complete Windows Update history

Get-HotFix queries the Win32_QuickFixEngineering WMI class. That class reports updates supplied through Component-Based Servicing (CBS). It does not return every update delivered through Microsoft Installer (MSI) or the Windows Update website and catalog, according to Microsoft’s Get-HotFix documentation.

That means a KB visible in Settings may not appear in Get-HotFix. Use this distinction when deciding which command to run:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Requirement Best method What it reports
See the normal Windows Update history Settings or the Windows Update Agent PowerShell query Windows Update history events, including operations and results
Check whether a servicing hotfix is installed Get-HotFix Updates reported through CBS/QFE
Investigate scan or installation failures Get-WindowsUpdateLog and Windows diagnostic logs Detailed troubleshooting information, not a clean installed-update list

Query the actual Windows Update history with PowerShell

To retrieve the history used by the Windows Update Agent, open PowerShell and run:

$session = New-Object -ComObject Microsoft.Update.Session
$searcher = $session.CreateUpdateSearcher()
$count = $searcher.GetTotalHistoryCount()

$searcher.QueryHistory(0, $count) |
Select-Object Date, Title, Description, Operation, ResultCode, HResult

The command creates a Windows Update session, asks how many history events exist, retrieves them, and selects useful fields. Microsoft’s Windows Update Agent API documentation describes these as update history events.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To show the newest events first:

$session = New-Object -ComObject Microsoft.Update.Session
$searcher = $session.CreateUpdateSearcher()
$count = $searcher.GetTotalHistoryCount()

$searcher.QueryHistory(0, $count) |
Sort-Object Date -Descending |
Select-Object Date, Title, Description, Operation, ResultCode, HResult

Date identifies when the event occurred. Title usually contains the update name or KB number. Operation, ResultCode, and HResult help distinguish a successful installation from a download, failure, or other activity.

Export the history to CSV

For filtering in Excel or sharing with a support technician, export the results:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

$session = New-Object -ComObject Microsoft.Update.Session
$searcher = $session.CreateUpdateSearcher()
$count = $searcher.GetTotalHistoryCount()

$searcher.QueryHistory(0, $count) |
Select-Object Date, Title, Description, Operation, ResultCode, HResult |
Export-Csv “$env:USERPROFILE\Desktop\WindowsUpdateHistory.csv” -NoTypeInformation

The file is saved as WindowsUpdateHistory.csv on the current user’s desktop.

Why this query may show duplicate-looking entries

QueryHistory returns update events, not necessarily one unique row for each KB or cumulative update. One update can create multiple events for actions such as downloading, installing, failing, or being uninstalled.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Portable retro Game Emulator Console Batocera v40 500GB-Boot-setting enabled Plug & Play Game System Bulit In-14.5K+Games 550+ 3D No Dupes 39 Systems USB3.1for PC/Laptop/WinPC
  • 【IMPORTANT – Technical Skill Required】To boot from it, you must enter your computer’s BIOS/UEFI, change the boot order, and disable Secure Boot (sometimes also enable Legacy/CSM mode). These are low‑level system settings, not simple software changes. If you are not familiar with BIOS menus or have never changed boot options, we suggest not buying this product. We provide illustrated manuals and video guides, but we cannot assist remotely. You need basic computer skills. Please read the manual carefully before starting – it will save you time and trouble.
  • 【UNIQUE Game Collection】14,000+ NO-DUPLICATE Games & 550+ 3D Titles *"Enjoy a carefully curated library of 14,000+ handpicked games , including 550+ premium 3D adventure, racing, and action classics. Pre-installed with 39 legendary game systems for authentic retro gaming."*
  • 【Plug & Play in 5 SECONDS】Instant Setup, No Hassle. "Start playing in seconds! Simply connect the Type-C cable to your device—no installations, downloads, or technical skills needed. Just change your computer's boot settings to start from USB, and your PC or laptop transforms into a retro gaming console instantly."
  • 【BATOCERA v40】Smarter Gaming Experience Powered by the newest Batocera v40 system (2024 release), enhanced 3D performance—no complex partitioning required. Only supports X86-based Windows and Mac computers.
  • 【Wide OS Compatibility】Driver-Free for Windows & Linux "Seamlessly compatible with modern operating systems (Windows 7/8/10/11 and Linux). Just change your boot settings to start from USB—no driver installations or setup needed. Designed for hassle-free, instant use on PCs, laptops, and mini-computers."

Do not assume that every row means a successful installation. Inspect the operation and result fields before drawing conclusions. If you need a simple answer to “is this servicing KB installed?”, Get-HotFix -Id may be easier, provided the update is reported through CBS.

Check Windows Update history from CMD

Legacy WMIC command

On systems that still include WMIC, this command searches the QFE list for a particular KB:

wmic qfe get hotfixid | find “KB1234567”

For multiple exact KBs:

wmic qfe get hotfixid | find “KB4012212” & wmic qfe get hotfixid | find “KB4012215” & wmic qfe get hotfixid | find “KB4015549”

Do not use WMIC as the default solution for new instructions. Microsoft says WMIC is removed by default from Windows 11 24H2 and 25H2 installations and may be re-added as a Feature on Demand. It was also removed during upgrades to 25H2. Microsoft says it will be completely removed in the next Windows 11 feature update in 2026. See Microsoft’s WMIC removal guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Run the supported PowerShell query from CMD

You can stay in Command Prompt and invoke PowerShell’s Windows Update Agent query:

powershell.exe -NoProfile -Command “$s=New-Object -ComObject Microsoft.Update.Session; $q=$s.CreateUpdateSearcher(); $n=$q.GetTotalHistoryCount(); $q.QueryHistory(0,$n) | Select-Object Date,Title,Description,Operation,ResultCode,HResult”

This is preferable to WMIC when the requirement is the full Windows Update history rather than only the CBS/QFE list. Microsoft’s WMIC migration guidance documents invoking PowerShell from CMD.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Do not confuse update history with WindowsUpdate.log

The following command creates a readable diagnostic log:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Get-WindowsUpdateLog

It merges Windows Update ETL trace files into a static WindowsUpdate.log file. It is useful for investigating scan, download, orchestration, or installation problems, but it is not a formatted replacement for the Update history page. Running the command again is required to create a newer merged log. See Microsoft’s Windows Update logs documentation.

Other diagnostic locations include:

  • C:\Windows\Logs\WindowsUpdate
  • C:\ProgramData\USOShared\Logs
  • %systemroot%\Logs\CBS

Use these locations when troubleshooting. For a list of updates and their dates, use Settings or the Windows Update Agent query.

Which command should you use?

Question Command
What update events does Windows Update know about? PowerShell COM query using QueryHistory
Is a specific CBS-serviced KB installed? Get-HotFix -Id KB1234567
Which servicing hotfixes are installed? Get-HotFix
Can I query another computer’s QFE list? Get-HotFix -ComputerName COMPUTERNAME
Why did an update fail? QueryHistory with result fields, followed by Windows Update and CBS logs
Am I following an old WMIC guide? Replace WMIC with Get-HotFix or the Windows Update Agent query

FAQ

Does Get-HotFix show every Windows update?

No. Get-HotFix reads Win32_QuickFixEngineering and reports CBS-serviced updates. Updates delivered through MSI or the Windows Update website/catalog may not appear. Use the Windows Update Agent QueryHistory command for Settings-style history.

Why is a KB visible in Settings but missing from Get-HotFix?

The update may not be supplied through Component-Based Servicing, or the two views may be reporting different update activity. Get-HotFix is a QFE/CBS list, while Windows Update history contains update events from the Windows Update Agent.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I use WMIC on Windows 11?

It may still exist on some installations, but it is not dependable on current Windows 11. WMIC is absent by default from newer 24H2 and 25H2 installations, may be re-added as a Feature on Demand, and is scheduled for complete removal in the next Windows 11 feature update in 2026.

Does Windows Update history contain only successful installations?

No. QueryHistory returns events. These can represent downloads, installations, failures, or uninstall-related activity. Check Operation, ResultCode, and HResult instead of treating every returned row as a successful install.

Where does the PowerShell export save the CSV file?

The supplied command saves it to the current user’s desktop as WindowsUpdateHistory.csv, using the path $env:USERPROFILE\Desktop\WindowsUpdateHistory.csv.

The Bottom Line

Use Get-HotFix for a quick check of CBS-serviced KBs, but use the Windows Update Agent PowerShell query when you need the same general event history represented in Settings. CMD users can call that PowerShell query with powershell.exe -Command. Treat wmic qfe as a legacy command because it is already missing from many current Windows 11 installations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.