What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
KB4052623 is a Microsoft Defender Antivirus antimalware-platform update, not a normal Windows 10 cumulative update. First check whether Defender already has a current platform version; Windows Update can keep displaying a failed entry even after Defender is working. If the platform is genuinely old, install the newest matching package from the Microsoft Update Catalog, then repair Windows Update or system files only if necessary.
What KB4052623 is—and what it is not
KB4052623 is the recurring Microsoft Defender Antivirus antimalware platform update. Microsoft describes platform updates as monthly product updates delivered through Windows Update, WSUS, Configuration Manager and other management systems. The KB number stays the same while the platform version changes. Check the current listing rather than relying on an old forum post: Microsoft Defender Antivirus updates.
| Update type | What it changes |
|---|---|
| KB4052623 | Defender antimalware platform, service and product components |
| KB2267602 and similar intelligence updates | Security-intelligence definitions used to detect threats |
| Windows 10 cumulative update | Windows operating-system fixes and security patches |
| Malicious Software Removal Tool | A separate, periodic malware-removal utility |
KB4052623 matters only where Microsoft Defender Antivirus is installed and active or managed. A third-party antivirus product can place Defender in passive or disabled mode, changing which updates apply.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsWhy the notification can return every few minutes
“Every 10 minutes” is an observed retry interval, not a Microsoft-documented timer. Common causes include:
#1 Best Overall
- Fresh USB Install With Key code Included
- 24/7 Tech Support from expert Technician
- Top product with Great Reviews
- Windows Update is retrying a failed platform installation.
- Defender installed the platform, but Windows Update has stale detection or history data.
- A partial or corrupted platform directory is blocking replacement.
- The Windows Update cache or servicing metadata is damaged.
- Windows component-store or system-file corruption prevents installation.
- Third-party security software, hardening tools or policy settings interfere with Defender.
- WSUS, Configuration Manager, Intune or another management service is offering an outdated or mismatched package.
- The package does not match the Windows release, architecture or Defender channel.
Step 1: Check Defender’s real status
Open Windows PowerShell as administrator and run:
Get-MpComputerStatus |
Format-List AMProductVersion,AMServiceVersion,AMEngineVersion,
AntivirusEnabled,RealTimeProtectionEnabled,AntivirusSignatureAge
AMProductVersion is the installed Defender platform version. AMServiceVersion identifies the Defender service, and AMEngineVersion identifies the scanning engine. The enabled fields show whether antivirus and real-time protection are active; AntivirusSignatureAge shows how old the security intelligence is. Microsoft uses Get-MpComputerStatus for this verification guidance: Microsoft Defender update guidance.
- Current platform and protection enabled: the recurring entry is probably stale detection or history. Restart, update Defender from Windows Security, and check the status again before making invasive changes.
- Old platform: install the newest matching KB4052623 package manually.
- Defender disabled or unavailable: treat it as a security issue. Identify the active antivirus or management policy instead of merely suppressing the notification.
- Command fails or returns incomplete data: repair Windows and Defender components, then inspect logs.
Inspect the installed platform folders
Platform versions are normally under:
C:ProgramDataMicrosoftWindows DefenderPlatform
ProgramData is hidden by default. Record the folder names and compare them with AMProductVersion. Multiple versions can provide a rollback path. Do not blindly delete the directory; doing so can remove working files and the previous platform needed for recovery.
Step 2: Install the newest KB4052623 package manually
- Open the Microsoft Update Catalog search for KB4052623.
- Choose the newest Current Channel (Broad) entry appropriate for the computer.
- Match the package to the Windows 10 release, edition and architecture (x86, amd64 or arm64 where offered).
- Download it and run the installer as administrator.
- Restart if requested.
- Run the status command again and compare
AMProductVersionwith the catalog entry.
The catalog showed version 4.18.26060.3008, dated July 6, 2026, in an August 18, 2026 search. That is a dated observation, not a permanent version number; always use the newest matching listing. Catalog installers may run silently, and a normal Windows Update history entry is not guaranteed. Microsoft documents supported architectures and distribution methods in Manage how and where Defender receives updates.
Step 3: Update Defender security intelligence separately
A platform update and a signature update are different operations. After the platform is fixed, update security intelligence with:
& "$env:ProgramFilesWindows DefenderMpCmdRun.exe" -SignatureUpdate
To request Microsoft’s update source directly:
& "$env:ProgramFilesWindows DefenderMpCmdRun.exe" -SignatureUpdate -MMPC
Microsoft documents these commands and UNC-based update methods in its Defender update documentation. Successful signature updating does not prove that KB4052623 installed, and the reverse is also true.
Step 4: Reset the Windows Update cache
Use this step when the platform is outdated or the normal installation fails. Open Command Prompt as administrator and run:
net stop wuauserv
net stop bits
net stop cryptSvc
ren %windir%SoftwareDistribution SoftwareDistribution.old
ren %windir%System32catroot2 catroot2.old
net start cryptSvc
net start bits
net start wuauserv
Restart Windows and try KB4052623 again. This Microsoft-documented sequence rebuilds cache and catalog state; it does not repair damaged Defender binaries, permissions or the component store. The renamed folders may temporarily consume disk space. See Microsoft’s Windows Update troubleshooting procedure.
Step 5: Repair Windows components and system files
In an elevated Command Prompt, run these commands in order:
DISM /Online /Cleanup-Image /RestoreHealth
sfc /scannow
DISM repairs the online component store; SFC then checks and replaces protected system files. Restart after both commands complete and retry the update. DISM normally uses Windows Update as its repair source. If it reports that source files cannot be found, use installation media or an ISO matching the installed Windows 10 release—never a random or mismatched download.
Rank #2
- Comprehensive Solution: This Windows 10 reinstall DVD provides a complete solution for resolving various system issues, including crashes, malware infections, boot failures, and performance slowdowns. Repair, Recover, Restore, and Reinstall any version of Windows.
- USB will work on any type of computer (make or model). Creates a new copy of Windows! DOES NOT INCLUDE product key.
- Windows not starting up? NT Loader missing? Repair Windows Boot Manager (BOOTMGR), NTLDR, and so much more with this DVD. Clean Installation: Allows you to perform a fresh installation of Windows 11 64-bit, effectively wiping the system and starting from a clean slate.
- Step by Step instructions on how to fix Windows 10 issues. Whether it be broken, viruses, running slow, or corrupted our disc will serve you well
- Please remember that this DVD does not come with a KEY CODE. You will need to obtain a Windows Key Code in order to use the reinstall option
Step 6: Roll back a platform that broke protection
If Defender stopped working immediately after a platform update, rollback is a recovery measure. Microsoft documents:
MpCmdRun.exe -RevertPlatform
To return to the platform shipped with the operating system instead, Microsoft documents:
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →MpCmdRun.exe -ResetPlatform
Run the command from a real installed platform directory:
cd /d "%ProgramData%MicrosoftWindows DefenderPlatform"
dir
"C:ProgramDataMicrosoftWindows DefenderPlatform<platform-version>MpCmdRun.exe" -RevertPlatform
Replace <platform-version> with an actual folder name shown by dir. Do not copy a historical path from a forum answer. Rollback leaves the machine on an older platform, so after protection is restored, install a newer release when one is offered. The commands and limitations are covered in Microsoft’s rollback guidance.
If KB4052623 still repeats
Capture the exact failure
- Record the KB4052623 version and the complete Windows Update error.
- Check Event Viewer entries for Windows Update and servicing.
- Review
C:WindowsTempMpSigStub.log, when present. - Collect Defender operational logs,
Get-MpComputerStatusoutput and the platform-folder listing.
Codes such as 0x80070643, 0x8024200B, 0x80070005 and 0x80073701 describe reported failure classes, not one universal cause. Microsoft Q&A troubleshooting for KB4052623 specifically requests the platform version and MpSigStub.log: KB4052623 installation guidance.
Check management and security software
On a business device, verify WSUS, Configuration Manager, Intune, Group Policy and endpoint-security rules with the administrator. A local catalog installer can be rejected or overwritten by central policy. If third-party antivirus is installed, use that vendor’s compatibility or removal procedure; do not delete Defender files and do not install another antivirus merely to hide the prompt.
Recommended Free Tools
Confirm the Windows 10 edition
Consumer Windows 10 Home and Pro, Enterprise, LTSC, IoT Enterprise and Windows Server have different servicing and availability rules. Identify the exact release (for example, 22H2 or an LTSC build), architecture and licensing status before applying a package. An in-place repair installation or Microsoft/organizational support may be appropriate when component corruption persists.
How to confirm the problem is solved
AMProductVersionandAMServiceVersionreport the installed current platform.AntivirusEnabledandRealTimeProtectionEnabledshow the intended protection state.- Defender security intelligence updates successfully.
- After a restart and a fresh Windows Update scan, KB4052623 no longer retries continuously.
A lingering historical entry alone does not prove that Defender is unprotected. The installed platform and protection status are the decisive checks.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

