Microsoft has released manual mitigations to assist IT administrators in resolving issues with Windows Server Update Services (WSUS) servers impacted by a known problem that leads to Windows Update scans failing or timing out.
This WSUS synchronization issue affects both client systems (Windows 10 version 1607 and later) and server platforms (Windows Server 2012 and later).
Administrators on affected WSUS servers are unable to deploy the latest Windows updates via WSUS or Configuration Manager due to prolonged synchronization times caused by accumulating public metadata that leads to timeouts.
Recently, Microsoft implemented service-side mitigations to tackle problems with newly installed or rebuilt WSUS servers following an increased impact noted on July 13th.
“Synchronization times and operations on WSUS servers have been restored to normal for new installations and rebuilds,” Microsoft stated.
Moreover, Microsoft released a manual fix for customers still facing synchronization issues or timeouts, aimed at restoring the normal functionality of their WSUS servers.
“Organizations with existing WSUS installations experiencing prolonged synchronization times can benefit from manual steps to remove unnecessary metadata,” the Windows Release Health Dashboard noted. “This metadata can be safely removed from existing WSUS installations.”
The following steps are required: Backup each SUSDB database, run a cleanup query on all SUSDB databases (including WSUS replicas) via SQL Management Studio, update the MaxXMLPerRequest value, and restore default settings.
After the cleanup process, the first Windows Update scan may take longer than usual; however, subsequent scans should return to normal timings.
“Post-cleanup, reindex the SUSDB, utilize the WSUS Server Cleanup Wizard, and then execute an IISReset or recycle the WsusPool application pool to clear cached catalog states,” Microsoft advised. “Note that the client-side DataStore.edb does not shrink automatically after deletions, which is expected and does not hinder scan performance.”
Microsoft has previously addressed similar WSUS issues impacting the deployment of the latest Windows updates in May, July, and August 2025.
Security teams report that 54% of successful attacks go undocumented while only 14% issue warnings. Unseen threats can traverse your network.
Picus’ whitepaper outlines methods to evaluate your SIEM and EDR rules through breach and attack simulations, ensuring no threats go undetected.
Source: www.bleepingcomputer.com




