Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

MS15-041: Description of the security update for the .NET Framework 4.5, 4.5.1, and 4.5.2 on Windows Vista Service Pack 2, Windows Server 2008 Service Pack 2, Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1: April 14, 2015


View products that this article applies to.

Summary

This update resolves a vulnerability in the Microsoft .NET Framework that could allow information disclosure if an attacker sends a specially crafted web request to an affected server that has custom error messages disabled. An attacker who successfully exploits the vulnerability would be able to view parts of a web configuration file that could expose sensitive information. To learn more about the vulnerability, see Microsoft Security Bulletin MS15-041.

Important To install this update, you must have Windows Installer 3.1 or a later version installed on the computer.

Note To resolve the vulnerability, you may need to apply multiple updates depending on the versions of .NET Framework you are running. For more information, see Affected versions of .NET Framework by this security bulletin.

↑ Back to the top


How to obtain and install the update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Get security updates automatically.

Method 2: Microsoft Download Center

You can obtain the stand-alone update package through the Microsoft Download Center. Follow the install instructions on the download page to install the update.

Download Download (KB3037581)

↑ Back to the top


More Information

Security update deployment information

Command-line switches for this update

Learn about the various command-line switches that are supported by this Microsoft .NET Framework update.

Restart requirements

This update does not require a system restart after you apply it unless files that are being updated are locked or are being used.

Removal information

Note We do not recommend that you remove any security update.

To remove this update, follow these steps:
  1. Open the Programs and Features item in Control Panel.
  2. Click View installed updates.
  3. Select update 3037581.
  4. Click Uninstall.

Replacement information

This security update replaces previously released update 2901126.

File information
The English (United States) version of this update installs files that have the attributes that are listed in the following tables. The dates and the times for these files are listed in Coordinated Universal Time (UTC). The dates and the times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and the times may change when you perform certain operations on the files.

For all supported x86-based versions of systems

GDR service branch
File nameFile versionFile sizeDateTime
Aspnet_perf.dll4.0.30319.3424941,62406-Feb-201500:48
aspnet_wp.exe4.0.30319.3424943,14406-Feb-201500:48
System.Web.ApplicationServices.dll4.0.30319.3424962,68804-Feb-201520:26
System.Web.Extensions.dll4.0.30319.342491,850,55204-Feb-201520:26
System.Web.dll4.0.30319.342495,456,52804-Feb-201520:26
System.Web.Mobile.dll4.0.30319.34249839,85604-Feb-201520:26
webengine.dll4.0.30319.3424924,71206-Feb-201500:48
webengine4.dll4.0.30319.34249509,59206-Feb-201500:48
msvcr120_clr0400.dll12.0.51689.34249875,68806-Feb-201500:48
LDR service branch
File nameFile versionFile sizeDateTime
Aspnet_perf.dll4.0.30319.3628541,61604-Feb-201514:13
aspnet_wp.exe4.0.30319.3628543,15204-Feb-201514:13
System.Web.ApplicationServices.dll4.0.30319.3628562,68004-Feb-201513:12
System.Web.Extensions.dll4.0.30319.362851,850,56004-Feb-201513:12
System.Web.dll4.0.30319.362855,457,56004-Feb-201513:12
System.Web.Mobile.dll4.0.30319.36285839,84804-Feb-201513:12
webengine.dll4.0.30319.3628524,71204-Feb-201514:13
webengine4.dll4.0.30319.36285509,57604-Feb-201514:13
msvcr120_clr0400.dll12.0.52285.36285875,68804-Feb-201514:13

For all supported x64-based versions of systems

GDR service branch
File nameFile versionFile sizeDateTime
Aspnet_perf.dll4.0.30319.3424945,20806-Feb-201501:01
Aspnet_perf.dll4.0.30319.3424941,62406-Feb-201500:48
aspnet_wp.exe4.0.30319.3424947,75206-Feb-201501:01
aspnet_wp.exe4.0.30319.3424943,14406-Feb-201500:48
System.Web.ApplicationServices.dll4.0.30319.3424962,68804-Feb-201520:26
System.Web.Extensions.dll4.0.30319.342491,850,55204-Feb-201520:26
System.Web.dll4.0.30319.342495,450,38406-Feb-201501:01
System.Web.dll4.0.30319.342495,456,52804-Feb-201520:26
System.Web.Mobile.dll4.0.30319.34249839,85604-Feb-201520:26
webengine.dll4.0.30319.3424926,76006-Feb-201501:01
webengine.dll4.0.30319.3424924,71206-Feb-201500:48
webengine4.dll4.0.30319.34249621,19206-Feb-201501:01
webengine4.dll4.0.30319.34249509,59206-Feb-201500:48
msvcr120_clr0400.dll12.0.51689.34249869,53606-Feb-201501:01
msvcr120_clr0400.dll12.0.51689.34249875,68806-Feb-201500:48
LDR service branch
File nameFile versionFile sizeDateTime
Aspnet_perf.dll4.0.30319.3628545,20004-Feb-201514:24
Aspnet_perf.dll4.0.30319.3628541,61604-Feb-201514:13
aspnet_wp.exe4.0.30319.3628547,75204-Feb-201514:24
aspnet_wp.exe4.0.30319.3628543,15204-Feb-201514:13
System.Web.ApplicationServices.dll4.0.30319.3628562,68004-Feb-201513:12
System.Web.Extensions.dll4.0.30319.362851,850,56004-Feb-201513:12
System.Web.dll4.0.30319.362855,450,88804-Feb-201514:24
System.Web.dll4.0.30319.362855,457,56004-Feb-201513:12
System.Web.Mobile.dll4.0.30319.36285839,84804-Feb-201513:12
webengine.dll4.0.30319.3628526,76004-Feb-201514:24
webengine.dll4.0.30319.3628524,71204-Feb-201514:13
webengine4.dll4.0.30319.36285621,19204-Feb-201514:24
webengine4.dll4.0.30319.36285509,57604-Feb-201514:13
msvcr120_clr0400.dll12.0.52285.36285869,54404-Feb-201514:24
msvcr120_clr0400.dll12.0.52285.36285875,68804-Feb-201514:13

Affected versions of .NET Framework by this security bulletin

Windows versionUpdates to install
Windows Vista SP2 and Windows Server 2008 SP23037573 for .NET Framework 2.0 SP2
3037578 for .NET Framework 4
3037581 for .NET Framework 4.5/4.5.1/4.5.2
Windows 7 SP1 and Windows Server 2008 R2 SP13037574 for .NET Framework 3.5.1
3037578 for .NET Framework 4
3037581 for .NET Framework 4.5/4.5.1/4.5.2

How to obtain help and support for this security update
Help for installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help for protecting your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

↑ Back to the top



Applies to

This article applies to the following:
  • Microsoft .NET Framework 4.5.2 when used with:
    • Windows Server 2008 R2 Service Pack 1
    • Windows 7 Service Pack 1
    • Windows Server 2008 Service Pack 2
    • Windows Vista Service Pack 2
  • Microsoft .NET Framework 4.5.1 when used with:
    • Windows Server 2008 R2 Service Pack 1
    • Windows 7 Service Pack 1
    • Windows Server 2008 Service Pack 2
    • Windows Vista Service Pack 2
  • Microsoft .NET Framework 4.5 when used with:
    • Windows Server 2008 R2 Service Pack 1
    • Windows 7 Service Pack 1
    • Windows Server 2008 Service Pack 2
    • Windows Vista Service Pack 2

↑ Back to the top


Keywords: atdownload, kbbug, kbexpertiseinter, kbfix, kblangall, kbsecreview, kbsecbulletin, kb, kbsecurity, kbsecvulnerability, kbmustloc

↑ Back to the top

Article Info
Article ID : 3037581
Revision : 1
Created on : 1/7/2017
Published on : 4/27/2015
Exists online : False
Views : 429