Case study

Windows 11 recovered after a stalled KB5120998 update without reinstalling

On 3 September 2026, we received a Windows 11 PC that powered on normally but crashed during every boot with 0xC000021A. The problems had begun around Windows Update. Rolling back the recent update did not stop the crash.

We repaired the existing installation by applying the exact official cumulative update package offline. The PC worked stably afterward, with its files, applications and settings preserved. Getting there required checking why rollback and other repairs had not worked.

Lees in het Nederlands →

What the first checks told us

0xC000021A means Windows cannot continue because a critical process or user-mode subsystem has terminated. It does not identify one file, driver or update as the cause.

There was no useful crash dump and no restore point. Memory tests found no errors, and the NVMe SSD remained consistently visible. These checks did not rule out every hardware fault, but gave us no direct explanation for the repeated crash.

We found damaged Windows components and repaired them. The original crash remained. Temporarily disabling an older driver and security software also made no difference, and Safe Mode crashed too. Repairing the component damage had therefore not been enough to restore startup.

The local update had not finished

The update and servicing logs pointed to KB5120998. On this PC, installation had stalled around a conflicting Windows Store Event Provider registration. Package registration and Windows components had not reached a fully completed update state.

Removing an older cumulative package version did not help either. The logs and package state gave us a reason to investigate the incomplete installation further, rather than keep removing packages.

The finding concerned an update that had not completed on this PC. It did not mean that KB5120998 generally causes 0xC000021A.

Applying the matching package offline

After data and relevant recovery copies were secured, we applied the exact official full x64 cumulative package to the Windows installation while it was not running. We verified the package's size and hash before using it.

The image then reported version 10.0.26200.9278. A component-store scan was clean, and a targeted check of a critical protected Windows file found no integrity violation.

The recovery work also included backing up and rebuilding the boot configuration, although it was not shown to be the cause of the original stop. Applying the full update package offline proved to be the turning point.

The first normal boot still ended once with 0xC0000001. On the following boot, Windows completed the remaining configuration and reached the sign-in screen.

The existing PC back in use

The PC worked stably after the repair, with its files, applications and settings preserved. There was no need for a clean Windows installation or the work of rebuilding that configuration.

For the diagnostic checks and technical procedures: