Saner CVEM Patch Installation Failure

Modified on Thu, 1 Oct at 8:22 AM

Remediation Job or Rule fails with Windows Installer exit code 1618

Issue

A Saner CVEM Remediation Job or Remediation Rule reports that a Windows patch failed to install. The patch package may download and validate successfully, but the endpoint returns installer exit code 1618 (0x00000652). This article explains why the failure occurs and how to restore patching without changing the job or rule configuration.

Symptoms

The remediation result shows the patch as failed. Saner agent logs may show exit code 1618, ERROR_INSTALL_ALREADY_RUNNING, or a message stating that another installation is already in progress. Retrying immediately often produces the same result. A manual installation of the same MSI package may also fail with code 1618.

Cause

Windows Installer permits only one MSI installation transaction at a time. When Saner CVEM starts the vendor installer while Windows Update, an application updater, a repair, an uninstall, or another deployment tool is already using MSIEXEC, Windows rejects the new request. Saner CVEM has completed its delivery and launch responsibilities; the native Windows Installer engine prevents concurrent execution. Therefore, this is an endpoint state or installer concurrency issue, not a failure of the Saner CVEM Remediation Job or Rule engine.

Validation

Confirm the failure details in Saner CVEM and note the patch name, timestamp, and installer exit code. On the endpoint, check Task Manager or approved administrative tooling for an active MSIEXEC process and identify the installation that owns it. Review Windows Event Viewer and the vendor installer log around the same timestamp. If permitted, run the identical installer manually under the same security context and with the same silent parameters. Reproducing code 1618 outside Saner CVEM confirms that Windows Installer contention is the cause.

Resolution

Allow the active installation, update, repair, or removal to finish. Do not terminate MSIEXEC while a legitimate installation is progressing, because doing so can leave software in an inconsistent state. If the process is confirmed as stalled, follow your organization’s change procedure to close the owning application, restart the Windows Installer service, or reboot the endpoint during an approved maintenance window. After the competing transaction has cleared, verify that no installation is pending and rerun the failed Saner CVEM Remediation Job. For a Remediation Rule, use the supported retry or wait for its next scheduled evaluation. Confirm that the patch status changes to installed and that the related vulnerability is reassessed as remediated.

Prevention

Schedule Saner CVEM remediation outside software distribution, Windows Update, application maintenance, and endpoint management windows. Avoid launching overlapping jobs against the same device group. Where operationally possible, use pilot rings and staggered schedules, and monitor endpoints for pending reboot or long-running installer activity before deployment. If code 1618 recurs frequently, identify the competing updater or deployment platform and coordinate maintenance ownership. Escalate to Saner support only when no concurrent installation exists, a manual installation succeeds under equivalent conditions, and repeated Saner CVEM attempts still fail; include the job identifier, endpoint details, timestamps, patch metadata, exit code, and relevant installer logs. Record the successful retry and close the change ticket with evidence for future incident correlation.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article