http://stackoverflow.com/questions/454048/what-is-the-differ...
The signature is distributed alongside the binaries.
I'm not certain if the Windows Update system uses the same Autheticode system used for application binaries, but you can start reading here:
https://msdn.microsoft.com/en-us/library/ms537361%28v=vs.85%...
It verifies that the signer had access to the private key, and that the data signed by the private key is the same data that you are verifying with the public key.
It's like the other checksums (SHA-1/MD5/etc) with the addition of identity verification (so long as you can trust that the private-public keypair used to sign it is only accessible to parties you trust).
(I am not experienced in cryptography. This explanation might be a little simplistic.)