Case study

Windows 11 recovered after a stalled KB5120998 update without reinstalling

On 3 September 2026, we received a Windows 11 PC that powered on normally but crashed during every boot with 0xC000021A.

The problem had appeared around Windows Update. We rolled the recent update back, but the same crash remained.

Lees in het Nederlands →

Check other causes first

0xC000021A means Windows cannot continue because a critical process or user-mode subsystem has terminated. The code does not identify one file, driver or update as the cause.

There was no useful crash dump and no restore point. Memory testing found no fault and the NVMe SSD remained consistently visible.

Windows did contain damaged components. They could be repaired, but the crash remained. Temporarily disabling an older driver and security software did not change the failure. Safe Mode also crashed.

The update had not completed

Update and servicing logs referenced KB5120998, an optional preview update Microsoft published on 27 August 2026 for Windows 11 24H2 and 25H2.

The local logs showed that installation on this PC had stalled around a conflicting Windows Store Event Provider registration. Package registration and Windows components were not left in one fully completed update state.

Microsoft had not documented a general KB5120998/0xC000021A boot issue. This diagnosis applied to this PC.

Rollback was not enough

We also removed an older cumulative package version. Package registration, Windows components and files still did not return to a known healthy previous state.

Rather than remove more packages, we selected the exact official package for this Windows installation and verified it before applying it.

KB5120998 applied to the offline installation

After data and relevant recovery copies were secured, the official x64 package for KB5120998 was applied to the Windows installation while it was offline.

The image then reported build 26200.9278. The component-store check was clean and a targeted check of a critical Windows file found no integrity violation.

The first normal boot still ended once with 0xC0000001. On the following boot, Windows completed the remaining configuration and reached the sign-in screen.

We tested repeated starts and the existing applications and settings remained in place.

Why we did not reinstall Windows

A clean installation would also have meant rebuilding the applications and configuration on this PC. Because the existing installation could be repaired and then validated, that rebuild was unnecessary.

This case does not show that KB5120998 generally causes 0xC000021A. It involved one machine on which the update had not completed locally.

Technical procedures: