What is the MSU file format?
.MSU is an update installer file format used by the Windows Update application, introduced with Windows Vista. An .msu file stores file and application updates - security patches, system updates, or cumulative fixes - packaged for offline or standalone deployment.
Each .msu file contains the following elements:
- Windows Update metadata - information describing each update package contained in the
.msufile. - At least one CAB archive - these store the actual update payload data.
- An XML file - describes the contents and dependencies of the
.msupackage. - A properties file - read by
Wusa.exeso it can identify the correct update and apply it automatically. - A
WSUSSCAN.cabfile - used for compatibility scanning with Windows Server Update Services (WSUS).
.MSU is a proprietary Microsoft format. The internal container structure has evolved over Windows generations: legacy packages (Vista through Windows 8.1) are CAB-based and carry the MSCF signature, while modern packages (Windows 10 and later) use an OPC/ZIP container starting with the PK signature. In either case, .msu files are typically compressed to reduce download and storage size, as update packages can be quite large and are released frequently.
Updates in .msu files are installed by the Windows Update Standalone Installer, Wusa.exe, located in the System32 folder. The installer uses the Windows Update Agent API to apply changes. On newer systems, DISM (dism.exe /Online /Add-Package) and the PowerShell cmdlet Add-WindowsPackage are also supported for scripted or image-based deployments. The contents of an .msu file can be extracted manually using expand.exe or 7-Zip, and then installed via appropriate Windows command-line instructions.
Security & safety
RISK: LOWA genuine MSU from Microsoft (Windows Update or the Microsoft Update Catalog) is digitally signed and safe - it is how official patches ship. The real risks are: (1) installing an MSU from an untrusted source (only download from catalog.update.microsoft.com or support.microsoft.com), since a tampered update could carry malware; and (2) applying the wrong package - 'not applicable to your computer' means the MSU targets a different Windows version/architecture, not that it's broken. MSU files can be large and a botched manual update can disrupt the system, so prefer Windows Update when possible and create a restore point before manual servicing.
Format details
in a nutshellPrograms that open MSU files
Technical details
deep spec| Container format | Proprietary Microsoft package; legacy MSU (Vista-Windows 8.1) uses a CAB-based container, modern MSU (Windows 10/11) uses an OPC/ZIP-based container |
| Magic bytes | Legacy: 4D 53 43 46 (MSCF) at offset 0; modern: 50 4B 03 04 (PK) at offset 0 - format era determines which signature appears |
| MIME type | application/octet-stream |
| Primary installer | wusa.exe (Windows Update Standalone Installer) located in %SystemRoot%\System32 |
| Installer API | Windows Update Agent (WUA) API - the same engine used by the Windows Update background service |
| Payload storage | Actual update files stored in one or more compressed .cab archives embedded within the package container |
| Metadata format | XML-based Windows Update metadata describing package identity, version, and applicability conditions |
| WSUS catalog file | Each MSU includes a WSUSSCAN.cab file enabling compatibility scanning with Windows Server Update Services |
| Applicability rules | Embedded XML rules verified at install time against OS version, processor architecture, and installed component state |
| Additional installers | DISM (dism.exe /Online /Add-Package) and PowerShell Add-WindowsPackage both support MSU-based deployment |
| Manual extraction | Contents extractable with expand.exe or 7-Zip; inner .cab files can then be applied with dism.exe or pkgmgr.exe |
| Silent installation | wusa.exe accepts /quiet, /norestart, and /log switches for fully unattended scripted deployment |
| Scope | Targets Windows OS components and system files only; not used for third-party or user-mode application installs |
| Compression | Payload .cab files use LZX or MSZIP compression; modern OPC/ZIP MSUs also apply Deflate at the outer container level |
| Architecture support | Separate MSU packages are released per processor architecture: x86, x64 (AMD64), ARM, and ARM64 |
| Released | 2007 (Windows Vista / Windows Update Standalone Installer, wusa.exe) |
| Specification | support.microsoft.com |
MSU conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about MSU files.