What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

KB4052623 is a Microsoft Defender Antivirus antimalware-platform update, not a normal Windows 10 cumulative update. First check whether Defender already has a current platform version; Windows Update can keep displaying a failed entry even after Defender is working. If the platform is genuinely old, install the newest matching package from the Microsoft Update Catalog, then repair Windows Update or system files only if necessary.

What KB4052623 is—and what it is not

KB4052623 is the recurring Microsoft Defender Antivirus antimalware platform update. Microsoft describes platform updates as monthly product updates delivered through Windows Update, WSUS, Configuration Manager and other management systems. The KB number stays the same while the platform version changes. Check the current listing rather than relying on an old forum post: Microsoft Defender Antivirus updates.

Update type What it changes
KB4052623 Defender antimalware platform, service and product components
KB2267602 and similar intelligence updates Security-intelligence definitions used to detect threats
Windows 10 cumulative update Windows operating-system fixes and security patches
Malicious Software Removal Tool A separate, periodic malware-removal utility

KB4052623 matters only where Microsoft Defender Antivirus is installed and active or managed. A third-party antivirus product can place Defender in passive or disabled mode, changing which updates apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the notification can return every few minutes

“Every 10 minutes” is an observed retry interval, not a Microsoft-documented timer. Common causes include:

  • Windows Update is retrying a failed platform installation.
  • Defender installed the platform, but Windows Update has stale detection or history data.
  • A partial or corrupted platform directory is blocking replacement.
  • The Windows Update cache or servicing metadata is damaged.
  • Windows component-store or system-file corruption prevents installation.
  • Third-party security software, hardening tools or policy settings interfere with Defender.
  • WSUS, Configuration Manager, Intune or another management service is offering an outdated or mismatched package.
  • The package does not match the Windows release, architecture or Defender channel.

Step 1: Check Defender’s real status

Open Windows PowerShell as administrator and run:

Get-MpComputerStatus |
  Format-List AMProductVersion,AMServiceVersion,AMEngineVersion,
  AntivirusEnabled,RealTimeProtectionEnabled,AntivirusSignatureAge

AMProductVersion is the installed Defender platform version. AMServiceVersion identifies the Defender service, and AMEngineVersion identifies the scanning engine. The enabled fields show whether antivirus and real-time protection are active; AntivirusSignatureAge shows how old the security intelligence is. Microsoft uses Get-MpComputerStatus for this verification guidance: Microsoft Defender update guidance.

  • Current platform and protection enabled: the recurring entry is probably stale detection or history. Restart, update Defender from Windows Security, and check the status again before making invasive changes.
  • Old platform: install the newest matching KB4052623 package manually.
  • Defender disabled or unavailable: treat it as a security issue. Identify the active antivirus or management policy instead of merely suppressing the notification.
  • Command fails or returns incomplete data: repair Windows and Defender components, then inspect logs.

Inspect the installed platform folders

Platform versions are normally under:

C:ProgramDataMicrosoftWindows DefenderPlatform

ProgramData is hidden by default. Record the folder names and compare them with AMProductVersion. Multiple versions can provide a rollback path. Do not blindly delete the directory; doing so can remove working files and the previous platform needed for recovery.

Step 2: Install the newest KB4052623 package manually

  1. Open the Microsoft Update Catalog search for KB4052623.
  2. Choose the newest Current Channel (Broad) entry appropriate for the computer.
  3. Match the package to the Windows 10 release, edition and architecture (x86, amd64 or arm64 where offered).
  4. Download it and run the installer as administrator.
  5. Restart if requested.
  6. Run the status command again and compare AMProductVersion with the catalog entry.

The catalog showed version 4.18.26060.3008, dated July 6, 2026, in an August 18, 2026 search. That is a dated observation, not a permanent version number; always use the newest matching listing. Catalog installers may run silently, and a normal Windows Update history entry is not guaranteed. Microsoft documents supported architectures and distribution methods in Manage how and where Defender receives updates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Step 3: Update Defender security intelligence separately

A platform update and a signature update are different operations. After the platform is fixed, update security intelligence with:

& "$env:ProgramFilesWindows DefenderMpCmdRun.exe" -SignatureUpdate

To request Microsoft’s update source directly:

& "$env:ProgramFilesWindows DefenderMpCmdRun.exe" -SignatureUpdate -MMPC

Microsoft documents these commands and UNC-based update methods in its Defender update documentation. Successful signature updating does not prove that KB4052623 installed, and the reverse is also true.

Step 4: Reset the Windows Update cache

Use this step when the platform is outdated or the normal installation fails. Open Command Prompt as administrator and run:

net stop wuauserv
net stop bits
net stop cryptSvc

ren %windir%SoftwareDistribution SoftwareDistribution.old
ren %windir%System32catroot2 catroot2.old

net start cryptSvc
net start bits
net start wuauserv

Restart Windows and try KB4052623 again. This Microsoft-documented sequence rebuilds cache and catalog state; it does not repair damaged Defender binaries, permissions or the component store. The renamed folders may temporarily consume disk space. See Microsoft’s Windows Update troubleshooting procedure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Step 5: Repair Windows components and system files

In an elevated Command Prompt, run these commands in order:

DISM /Online /Cleanup-Image /RestoreHealth
sfc /scannow

DISM repairs the online component store; SFC then checks and replaces protected system files. Restart after both commands complete and retry the update. DISM normally uses Windows Update as its repair source. If it reports that source files cannot be found, use installation media or an ISO matching the installed Windows 10 release—never a random or mismatched download.

Rank #2
Ralix Reinstall USB Compatible with Windows 10 All Versions 32/64 bit. Recover, Restore, Repair Boot USB, and Install to Factory Default Will Fix PC Easy!
  • Comprehensive Solution: This Windows 10 reinstall DVD provides a complete solution for resolving various system issues, including crashes, malware infections, boot failures, and performance slowdowns. Repair, Recover, Restore, and Reinstall any version of Windows.
  • USB will work on any type of computer (make or model). Creates a new copy of Windows! DOES NOT INCLUDE product key.
  • Windows not starting up? NT Loader missing? Repair Windows Boot Manager (BOOTMGR), NTLDR, and so much more with this DVD. Clean Installation: Allows you to perform a fresh installation of Windows 11 64-bit, effectively wiping the system and starting from a clean slate.
  • Step by Step instructions on how to fix Windows 10 issues. Whether it be broken, viruses, running slow, or corrupted our disc will serve you well
  • Please remember that this DVD does not come with a KEY CODE. You will need to obtain a Windows Key Code in order to use the reinstall option
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Step 6: Roll back a platform that broke protection

If Defender stopped working immediately after a platform update, rollback is a recovery measure. Microsoft documents:

MpCmdRun.exe -RevertPlatform

To return to the platform shipped with the operating system instead, Microsoft documents:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
MpCmdRun.exe -ResetPlatform

Run the command from a real installed platform directory:

cd /d "%ProgramData%MicrosoftWindows DefenderPlatform"
dir
"C:ProgramDataMicrosoftWindows DefenderPlatform<platform-version>MpCmdRun.exe" -RevertPlatform

Replace <platform-version> with an actual folder name shown by dir. Do not copy a historical path from a forum answer. Rollback leaves the machine on an older platform, so after protection is restored, install a newer release when one is offered. The commands and limitations are covered in Microsoft’s rollback guidance.

If KB4052623 still repeats

Capture the exact failure

  • Record the KB4052623 version and the complete Windows Update error.
  • Check Event Viewer entries for Windows Update and servicing.
  • Review C:WindowsTempMpSigStub.log, when present.
  • Collect Defender operational logs, Get-MpComputerStatus output and the platform-folder listing.

Codes such as 0x80070643, 0x8024200B, 0x80070005 and 0x80073701 describe reported failure classes, not one universal cause. Microsoft Q&A troubleshooting for KB4052623 specifically requests the platform version and MpSigStub.log: KB4052623 installation guidance.

Check management and security software

On a business device, verify WSUS, Configuration Manager, Intune, Group Policy and endpoint-security rules with the administrator. A local catalog installer can be rejected or overwritten by central policy. If third-party antivirus is installed, use that vendor’s compatibility or removal procedure; do not delete Defender files and do not install another antivirus merely to hide the prompt.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Confirm the Windows 10 edition

Consumer Windows 10 Home and Pro, Enterprise, LTSC, IoT Enterprise and Windows Server have different servicing and availability rules. Identify the exact release (for example, 22H2 or an LTSC build), architecture and licensing status before applying a package. An in-place repair installation or Microsoft/organizational support may be appropriate when component corruption persists.

How to confirm the problem is solved

  • AMProductVersion and AMServiceVersion report the installed current platform.
  • AntivirusEnabled and RealTimeProtectionEnabled show the intended protection state.
  • Defender security intelligence updates successfully.
  • After a restart and a fresh Windows Update scan, KB4052623 no longer retries continuously.

A lingering historical entry alone does not prove that Defender is unprotected. The installed platform and protection status are the decisive checks.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.