> Source: [sk183061](https://support.checkpoint.com/results/sk/sk183061)

# sk183061 - KB5050009 fails to install on Windows 11

| Property | Value |
|----------|-------|
| Solution ID | sk183061 |
| Date Created | 2025-01-22 |
| Last Modified | 2025-01-29 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X, R82.20, R82.10, R82, R81.20 |

## Symptoms

- * KB5050009 fails to install on Windows 11 with ErrorCode 0x80070005
* Possible trigger of WDAC policies protection event

## Cause

Check Point's Harmony Endpoint security protection against *Windows Defender Application Control* (WDAC) exploitations, mistakenly prevented Windows Update from writing into system folders causing the update to fail.  

This issue affected these Endpoint Security Client Versions:  

* E88.50
* E88.60
* E88.61

## Solution

Before you start with the workaround, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get the required script.

**Workaround:**

1. Disable WDAC protection using this remote command push operation: ***disable_wdac_protection.ps1***
2. Execute OS upgrade.
3. Re-enable WDAC protection using this remote command push operation: ***enable_wdac_protection.ps1***

To execute remote command from the Push Operations:  

1. Go to the **Push Operations** tab and click **Add**.
2. Select **Agent Settings** from the drop down, and then select **Remote Command** .  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1737557874673/Screenshot_4202501220908191.jpg)  

3. Click **Next**.
4. Click + and select the devices.
5. In the **Type** drop-down, select **Signed Power Shell**.
6. In the **User Settings** section, select **System user**.
7. In the **Script** section, click **Upload** and upload the script you have received from the Check Point Support.  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183061/Screenshot_6202501220938181.jpg)  

8. Select **Finish** .  

   The push operation will be sent to the selected clients. You can monitor the status of the operation from the **Push Operations** tab in the Harmony Endpoint Administrator Portal.

For more information, see [Performing Push Operations](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-Common-for-HEP/Performing-Push-Operations.htm)  

If the Remote Command Push Operation fails, see [sk181425](https://support.checkpoint.com/results/sk/sk181425).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
