Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

MS14-046: Description of the security update for the .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2: August 12, 2014


Introduction

This update resolves a vulnerability in the Microsoft .NET Framework that could bypass the Address Space Layout Randomization (ASLR) security feature if a user goes to a specially crafted website.

↑ Back to the top


Summary

Microsoft has released security bulletin MS14-046. Learn more about how to obtain the fixes included in this security bulletin:

↑ Back to the top


How to obtain help and support for this security update

Help installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

↑ Back to the top


More Information

Known issues with this security update

  • After you install security update 2966828 (described in Microsoft Security Bulletin MS14-046) for the Microsoft .NET Framework 3.5, and then you try to enable the Microsoft .NET Framework 3.5 optional feature in Windows Features for the very first time, the feature may not install. You may notice this failure if you "stage" the installation before you add the Microsoft .NET Framework 3.5 feature.




    To resolve this issue, install update 3005628.

    For more information about how to work around this issue, click the following article number to view the article in the Microsoft Knowledge Base:
    3002547  Enabling the Microsoft .NET Framework 3.5 optional Windows feature on Windows 8, Windows Server 2012, Windows 8.1, or Windows Server 2012 R2 may fail after you install security update 2966827 or 2966828

↑ Back to the top


Download information

This update is available for download from the Microsoft Download Center.

↑ Back to the top


Command-line switches for this update

Learn about the various command-line switches that are supported by this Microsoft .NET Framework update.

↑ Back to the top


Restart information

This update does not require a system restart after you apply it unless files that are being updated are locked or are being used.

↑ Back to the top


Update replacement information

This update does not replace any previously released update.

↑ Back to the top


Update removal information

Note We do not recommend that you remove any security update.

To remove this update, use the Programs and Features item in Control Panel.

↑ Back to the top


File information

The English (United States) version of this update installs files that have the attributes that are listed in the following downloadable .csv file. The dates and the times for these files are listed in Coordinated Universal Time (UTC). The dates and the times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and the times may change when you perform certain operations on the files.

The following .csv file is available for download from the Microsoft Download Center:

↑ Back to the top



Applies to

This article applies to the following:
  • Microsoft .NET Framework 3.5 when used with:
    • Windows 8.1
    • Windows Server 2012 R2

↑ Back to the top


Keywords: atdownload, kbbug, kbexpertiseinter, kbfix, kblangall, kbsecbulletin, kbsecreview, kbsecurity, kbsecvulnerability, kb, kbmustloc

↑ Back to the top

Article Info
Article ID : 2966828
Revision : 1
Created on : 1/7/2017
Published on : 10/7/2014
Exists online : False
Views : 222