Why windows still use port 80 for windows update

Reyan 0 Reputation points
2023-02-18T09:07:45.2766667+00:00

Hi,

Everyone already knows that Port 80 is vulnerable. But still, I can see my system is using port 80 for windows updates.

Is there any way to stop using port 80 for windows updates?,If I block port 80 for all the systems in my org for windows updates will it impact the win update process?

Why is MICROSFT still using port 80?

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,470 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,170 questions
Windows 10 Compatibility
Windows 10 Compatibility
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Compatibility: The extent to which hardware or software adheres to an accepted standard.
456 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,215 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,586 Reputation points
    2023-02-18T10:19:51.29+00:00

    Hi @Reyan

    Unfortunately , the http is required to download Windows update from WSUS. the https is used only for metadata. By default WSUS use the port 8530 for HTTP ad 8531 for HTTPS.

    Below a confirmation from Microsoft article: Configure the WSUS server's IIS web server to use SSL for some connections

    User's image

    Please don't forget to mark helpful answer as accepted


  2. Limitless Technology 43,951 Reputation points
    2023-02-20T13:16:23.91+00:00

    Hello

    Thank you for your question and reaching out. I can understand you are having query\issues related to Windows update ports uses 80.

    WSUS uses both port 80 for HTTP and 443 for HTTPS. Main reasons being:

    A) HTTP is easily cached by any (regular, forward) proxy.

    B) The updates are always digitally signed and thus tamper-resistant at the application level.

    C) You don't need a certificate management

    Reference :

    https://learn.microsoft.com/en-us/answers/questions/726098/is-windows-update-on-clients-is-end-to-end-encrypt

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

  3. Limitless Technology 43,951 Reputation points
    2023-02-20T13:16:33.62+00:00

    Double post

    0 comments No comments