Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

MS15-041: Description of the security update for the .NET Framework 3.5 on Windows 8 and Windows Server 2012: April 14, 2015


Introduction

This update resolves a vulnerability in the Microsoft .NET Framework that could allow information disclosure if an attacker sends a specially crafted web request to an affected server that has custom error messages disabled. An attacker who successfully exploits the vulnerability would be able to view parts of a web configuration file that could expose sensitive information.

↑ Back to the top


Summary

Microsoft has released security bulletin MS15-041. Learn more about how to obtain the fixes that are included in this security bulletin: 

↑ Back to the top


How to obtain help and support for this security update

Help installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help protect your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

↑ Back to the top


More information about this security update

↑ Back to the top


Download information

To install this update, install it from Microsoft Windows Update.

Additionally, you can install this update from the Microsoft Download Center.

↑ Back to the top


Command-line switches for this update

Learn about the various command-line switches that are supported by this Microsoft .NET Framework update.

↑ Back to the top


Restart information

This update does not require a system restart after you apply it unless files that are being updated are locked or are being used.

↑ Back to the top


Update replacement information

This update replaces the following updates:

2901120 MS14-009: Description of the security update for the .NET Framework 3.5 for Windows 8 and Windows Server 2012: February 11, 2014


↑ Back to the top


Update removal information

Note We do not recommend that you remove any security update.

To remove this update, use the Programs and Features item in Control Panel.

↑ Back to the top


File information

↑ Back to the top



Applies to

This article applies to the following:
  • Microsoft .NET Framework 3.5 when used with:
    • Windows Server 2012
    • Windows 8

↑ Back to the top


Keywords: atdownload, kbbug, kbexpertiseinter, kbfix, kblangall, kbsecbulletin, kbsecreview, kbsecurity, kbsecvulnerability, kb, kbmustloc

↑ Back to the top

Article Info
Article ID : 3037575
Revision : 1
Created on : 1/7/2017
Published on : 4/14/2015
Exists online : False
Views : 360