(I am not experienced in cryptography. This explanation might be a little simplistic.)
http://stackoverflow.com/questions/454048/what-is-the-differ...
It verifies that the signer had access to the private key, and that the data signed by the private key is the same data that you are verifying with the public key.
It's like the other checksums (SHA-1/MD5/etc) with the addition of identity verification (so long as you can trust that the private-public keypair used to sign it is only accessible to parties you trust).
The signature is distributed alongside the binaries.
I'm not certain if the Windows Update system uses the same Autheticode system used for application binaries, but you can start reading here:
https://msdn.microsoft.com/en-us/library/ms537361%28v=vs.85%...
The odds that parties outside of Microsoft have access to their update signing key is actually seems pretty likely given the Snowden revelations. Consider the Stuxnet distribution strategy -- what a boon it'd be to be able to deploy that sort of machine-specific payload via the built-in update kit.