.MSU

MSU File

Microsoft Update Standalone Package
Ask a question
QUICK ANSWER

An MSU file is a standalone Windows Update package - a single patch or cumulative update you install offline without the Windows Update service. Double-click it and wusa.exe handles the rest. For scripting or offline images, use DISM or PowerShell. Download MSU files only from the official Microsoft Update Catalog.

Developer: Microsoft Category: System Files MIME: application/octet-stream
OPENS ON Windows
Related: .NOMEDIA · .DLL · .TMP · .LNK

On this page

19k+ extensions indexed
Last reviewed Aug 16, 2026

Not sure what your file is?

Drop any file into our identifier - we read just the first bytes to name the format.

Identify a file

What is the MSU file format?

.MSU is an update installer file format used by the Windows Update application, introduced with Windows Vista. An .msu file stores file and application updates - security patches, system updates, or cumulative fixes - packaged for offline or standalone deployment.

Each .msu file contains the following elements:

  • Windows Update metadata - information describing each update package contained in the .msu file.
  • At least one CAB archive - these store the actual update payload data.
  • An XML file - describes the contents and dependencies of the .msu package.
  • A properties file - read by Wusa.exe so it can identify the correct update and apply it automatically.
  • A WSUSSCAN.cab file - used for compatibility scanning with Windows Server Update Services (WSUS).

.MSU is a proprietary Microsoft format. The internal container structure has evolved over Windows generations: legacy packages (Vista through Windows 8.1) are CAB-based and carry the MSCF signature, while modern packages (Windows 10 and later) use an OPC/ZIP container starting with the PK signature. In either case, .msu files are typically compressed to reduce download and storage size, as update packages can be quite large and are released frequently.

Updates in .msu files are installed by the Windows Update Standalone Installer, Wusa.exe, located in the System32 folder. The installer uses the Windows Update Agent API to apply changes. On newer systems, DISM (dism.exe /Online /Add-Package) and the PowerShell cmdlet Add-WindowsPackage are also supported for scripted or image-based deployments. The contents of an .msu file can be extracted manually using expand.exe or 7-Zip, and then installed via appropriate Windows command-line instructions.

Security & safety

RISK: LOW

A genuine MSU from Microsoft (Windows Update or the Microsoft Update Catalog) is digitally signed and safe - it is how official patches ship. The real risks are: (1) installing an MSU from an untrusted source (only download from catalog.update.microsoft.com or support.microsoft.com), since a tampered update could carry malware; and (2) applying the wrong package - 'not applicable to your computer' means the MSU targets a different Windows version/architecture, not that it's broken. MSU files can be large and a botched manual update can disrupt the system, so prefer Windows Update when possible and create a restore point before manual servicing.

Format details

in a nutshell
FULL NAMEMicrosoft Update Standalone Package
DEVELOPERMicrosoftsince 2007 (Windows Vista / Windows Update Standalone Installer, wusa.exe)
CATEGORYSystem Files
MIME TYPEapplication/octet-stream
TYPEWindows Update package (binary container holding metadata + CAB payload)
MAGIC BYTES · FILE SIGNATURE
OFFSET
00010203
HEX
504B0304
ASCII
PK··
Format varies by era. Legacy MSU files are CAB-based and may start with 'MSCF' (4D 53 43 46). Modern (Windows 10/11) MSU packages are OPC/ZIP containers starting with 'PK' (50 4B 03 04). Do not rely on the signature; identify by the .msu extension and internal *.cab / WSUSSCAN / properties files. Right-click 'Open archive' in 7-Zip reveals the contents either way.

Programs that open MSU files

Windows4 apps
7-Zip Open-source Right-click > 7-Zip > Open archive to inspect/extract the internal .cab and XML without installing.
Windows Update Standalone Installer (wusa.exe) Built-in Double-click the .msu; wusa.exe checks applicability and installs (reboot if asked). Silent: wusa.exe file.msu /quiet /norestart.
DISM (Deployment Image Servicing and Management) Built-in DISM /Online /Add-Package /PackagePath:C:\path\update.msu - installs to the running or an offline image; best for servicing.
PowerShell (Add-WindowsPackage) Built-in Add-WindowsPackage -Online -PackagePath update.msu - scriptable install of the MSU.

Technical details

deep spec
Container formatProprietary Microsoft package; legacy MSU (Vista-Windows 8.1) uses a CAB-based container, modern MSU (Windows 10/11) uses an OPC/ZIP-based container
Magic bytesLegacy: 4D 53 43 46 (MSCF) at offset 0; modern: 50 4B 03 04 (PK) at offset 0 - format era determines which signature appears
MIME typeapplication/octet-stream
Primary installerwusa.exe (Windows Update Standalone Installer) located in %SystemRoot%\System32
Installer APIWindows Update Agent (WUA) API - the same engine used by the Windows Update background service
Payload storageActual update files stored in one or more compressed .cab archives embedded within the package container
Metadata formatXML-based Windows Update metadata describing package identity, version, and applicability conditions
WSUS catalog fileEach MSU includes a WSUSSCAN.cab file enabling compatibility scanning with Windows Server Update Services
Applicability rulesEmbedded XML rules verified at install time against OS version, processor architecture, and installed component state
Additional installersDISM (dism.exe /Online /Add-Package) and PowerShell Add-WindowsPackage both support MSU-based deployment
Manual extractionContents extractable with expand.exe or 7-Zip; inner .cab files can then be applied with dism.exe or pkgmgr.exe
Silent installationwusa.exe accepts /quiet, /norestart, and /log switches for fully unattended scripted deployment
ScopeTargets Windows OS components and system files only; not used for third-party or user-mode application installs
CompressionPayload .cab files use LZX or MSZIP compression; modern OPC/ZIP MSUs also apply Deflate at the outer container level
Architecture supportSeparate MSU packages are released per processor architecture: x86, x64 (AMD64), ARM, and ARM64
Released2007 (Windows Vista / Windows Update Standalone Installer, wusa.exe)
Specificationsupport.microsoft.com

MSU conversions

Community Q&A

asked by users
Ask a quick question
Get help from people who work with MSU files. Be specific - include your system and software version.
No account needed · answers usually within a day

No questions yet - be the first to ask about MSU files.

Frequently asked questions

How do I install an MSU file?
Double-click it - the Windows Update Standalone Installer (wusa.exe) runs and installs the update, then asks to reboot if needed. For silent install use: wusa.exe file.msu /quiet /norestart.
How do I install an MSU offline or on an image?
Use DISM: DISM /Online /Add-Package /PackagePath:update.msu for the running system, or /Image:<path> for an offline image. PowerShell's Add-WindowsPackage does the same.
Why does it say 'this update is not applicable to your computer'?
The MSU is built for a different Windows version or CPU architecture, the update is already installed, or a prerequisite (servicing-stack or checkpoint update on 24H2+) is missing. Download the package that matches your exact build.
How do I extract the contents of an MSU?
Open it with 7-Zip ('Open archive') or run expand -f:* update.msu C:\out to pull out the internal .cab and XML files - useful for DISM offline servicing.
What is the difference between MSU and MSI?
MSU is a Windows Update package installed by wusa.exe/DISM; MSI is an application installer run by msiexec. Different purposes, different installers - they are not interchangeable.
Where do I download MSU update files?
From the official Microsoft Update Catalog (catalog.update.microsoft.com) by KB number. Only use Microsoft sources - third-party copies of system updates are a malware risk.

References

1Microsoft Learn - DISM package servicing (.cab/.msu)learn.microsoft.com
2Microsoft Learn - Add-WindowsPackage (PowerShell)learn.microsoft.com

Keep exploring

across the database

Top extensions this week

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.PARTPartial Download File
4.DATProgram Data File (generic)
5.EXEWindows Executable (Portable Executable)
6.BINCD/DVD Disc Image (BIN/CUE)
7.NOMEDIAAndroid No-Media Marker File
8.RPMSGRestricted Permission Message
9.MDMarkdown Document
10.TMPTemporary File

Related extensions

.NOMEDIAAndroid No-Media Marker File
.DLLDynamic Link Library
.TMPTemporary File
.LNKWindows Shell Link (Shortcut)
.PKGmacOS Installer Package
.ETLEvent Trace Log

Free file tools

An in-browser file identifier and image converter - everything runs on your device.

Open the toolbox

Browse file extensions A-Z