Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

MS16-035: Description of the security update for the .NET Framework 4.5.2 in Windows Vista Service Pack 2, Windows Server 2008 Service Pack 2, Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1: March 8, 2016


Clarification: September 14, 2016 This security update was re-released on May 10, 2016 for LDR (limited distribution release) customers. It was determined that there were some issues in certain printing scenarios because of a missing dependency. This update re-release was then made available to all customers, including GDR (general distribution release) customers, on August 11, 2016. 

May 10, 2016 This security update has been re-released and contains updated files. This re-release is intended for LDR (limited distribution release) content customers only. We determined that there were some issues in certain printing scenarios because of a missing dependency. If you use LDR content, we recommend that you apply this updated security update. There are no changes in this re-release for GDR (general distribution release) content customers.

↑ Back to the top


Summary

This update resolves a vulnerability in the Microsoft .NET Framework. The security feature bypass exists in a .NET Framework component that does not properly validate certain elements of a signed XML document. To learn more about this vulnerability, see Microsoft Security Bulletin MS16-035.

To install this update, you must have Windows Installer 3.1 or a later version installed on the computer.

↑ Back to the top


How to obtain and install this update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to get security updates automatically, see the "Turn on automatic updating in the Control Panel" section of this Safety & Security Center article.

Method 2: Microsoft Download Center

You can obtain the stand-alone update package through the Microsoft Download Center. To install this update, follow the install instructions on the download page.

Download Download security update 3135996

↑ Back to the top


Update deployment information

For deployment information about this update, see Microsoft Knowledge Base article 3141780 .

↑ Back to the top


Update removal information

Note We do not recommend that you remove any security update.

To remove this update, use the Programs and Features item in Control Panel.

Update restart information

This update does not require a system restart after you apply it unless files that are being updated are locked or are being used.

Update replacement information

This update replaces previously released update 3035490 .

File information
How to obtain help and support for this security update

↑ Back to the top



Applies to

This article applies to the following:
  • Microsoft .NET Framework 4.5.2 when used with:
    • Windows Server 2008 R2 Service Pack 1
    • Windows 7 Service Pack 1
    • Windows Server 2008 Service Pack 2
    • Windows Vista Service Pack 2

↑ Back to the top


Keywords: atdownload, kbbug, kbexpertiseinter, kbfix, kblangall, kbsecurity, kbsecbulletin, kbsecreview, kb, kbsecvulnerability, kbmustloc

↑ Back to the top

Article Info
Article ID : 3135996
Revision : 1
Created on : 1/7/2017
Published on : 9/14/2016
Exists online : False
Views : 425