You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

远程服务器Start-Process执行失败:PowerShell批量安装Windows补丁遇阻

远程安装Windows补丁KB5023333.msu失败的排查与解决
  • 先确认补丁文件已同步到远程服务器
    你的脚本默认假设C:\patches\KB5023333.msu已经存在于每台远程机器,但实际大概率没同步过去。先执行以下步骤把补丁传到远程:

    foreach ($computer in $computers) {
        # 创建远程目录(如果不存在)
        Invoke-Command -ComputerName $computer -Credential $mycreds -ScriptBlock {
            if (-not (Test-Path "C:\patches")) {
                New-Item -Path "C:\patches" -ItemType Directory | Out-Null
            }
        }
        # 从本地复制补丁到远程服务器的C盘共享
        Copy-Item -Path "本地补丁路径\KB5023333.msu" -Destination "\\$computer\C$\patches\" -Credential $mycreds
    }
    
  • 修正WUSA命令的参数格式与错误捕获
    原脚本里的路径引号转义容易出问题,而且没做错误排查,改成下面的脚本可以明确知道失败原因:

    $Result = Invoke-Command -ComputerName $computers -Credential $mycreds -ScriptBlock {
        $patchPath = "C:\patches\KB5023333.msu"
        # 先检查文件是否存在
        if (-not (Test-Path $patchPath)) {
            return @{ 
                ComputerName = $env:COMPUTERNAME; 
                Status = "Error"; 
                Message = "补丁文件不存在" 
            }
        }
        # 先尝试静默安装不重启,排查是否是重启逻辑导致的问题
        try {
            $process = Start-Process -FilePath "wusa.exe" `
                -ArgumentList "`"$patchPath`" /quiet /norestart" `
                -Wait -PassThru -ErrorAction Stop
            
            $statusMsg = switch ($process.ExitCode) {
                0 { "安装完成,无需重启" }
                3010 { "安装完成,需要重启" }
                2 { "用户取消操作" }
                87 { "参数输入错误" }
                default { "未知错误,退出码: $($process.ExitCode)" }
            }
    
            return @{
                ComputerName = $env:COMPUTERNAME
                ExitCode = $process.ExitCode
                Status = if ($process.ExitCode -eq 0 -or $process.ExitCode -eq 3010) { "Success" } else { "Failed" }
                Message = $statusMsg
            }
        } catch {
            return @{
                ComputerName = $env:COMPUTERNAME
                Status = "Error"
                Message = "执行出错: $($_.Exception.Message)"
            }
        }
    }
    # 查看所有机器的执行结果
    $Result | Format-Table -AutoSize
    
  • 确保远程会话拥有管理员权限
    补丁安装需要本地管理员权限,Invoke-Command可以直接添加-RunAsAdministrator参数(PowerShell 5.1及以上版本支持),强制以管理员身份执行脚本块:

    $Result = Invoke-Command -ComputerName $computers -Credential $mycreds -RunAsAdministrator -ScriptBlock {
        # 上面的脚本内容
    }
    
  • 检查远程服务器的Windows Update服务状态
    补丁安装依赖Windows Update服务,先确认服务处于运行状态:

    Invoke-Command -ComputerName $computers -Credential $mycreds -ScriptBlock {
        $wuService = Get-Service -Name wuauserv
        if ($wuService.Status -ne 'Running') {
            Start-Service -Name wuauserv
            Write-Host "已启动Windows Update服务"
        }
    }
    

内容的提问来源于stack exchange,提问作者krishna

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 03:52:59