Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

MS16-091: Description of the security update for the .NET Framework 4.6 and 4.6.1 in Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2: July 12, 2016

View products that this article applies to.

November 8, 2016 A detection change was made to account for the .NET Framework 4.6.1 hotfix rollup for customers who were not being correctly offered this security update for the .NET Framework 4.6.1. 

↑ Back to the top


This update resolves a vulnerability in the Microsoft .NET Framework. The vulnerability could cause information disclosure if an attacker uploads a specially crafted XML file to a web-based application. To learn more about this vulnerability, see Microsoft Security Bulletin MS16-091.

↑ Back to the top

More Information

Important All future security and nonsecurity updates for Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2 require update 2919355 to be installed. We recommend that you install update 2919355 on your Windows RT 8.1-based, Windows 8.1-based, or Windows Server 2012 R2-based computer so that you receive future updates.

↑ Back to the top

How to obtain and install this update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to get security updates automatically, see the "Turn on automatic updating in the Control Panel" section of this Safety & Security Center article.

Note For Windows RT 8.1, this update is available through Windows Update only.

Method 2: Microsoft Download Center

You can obtain the stand-alone update package through the Microsoft Download Center. To install this update, follow the install instructions on the download page.

Download Download security update 3164024

↑ Back to the top

Update deployment information

For deployment information about this update, see Microsoft Knowledge Base article 3170048 .

Update removal information

Note We do not recommend that you remove any security update.

To remove this update, use the Programs and Features item in Control Panel.

Update restart information

This update does not require a system restart after you apply it unless files that are being updated are locked or are being used.

Update replacement information

This update does not replace any previously released update.

File information

File hash

File namePackage hash SHA1Package hash SHA2

File attributes

The English (United States) version of this update installs files that have the attributes that are listed in the following tables. The dates and the times for these files are listed in Coordinated Universal Time (UTC). The dates and the times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and the times may change when you perform certain operations on the files.

For all supported ARM-based versions
File nameFile versionFile sizeDateTimePlatform
Msvcp120_clr0400.dll12.0.52242.36242602,08020-Jun-201619:23Not applicable
Msvcr120_clr0400.dll12.0.52242.36242634,33620-Jun-201619:23Not applicable,362,30420-May-201607:30Not applicable
For all supported x86-based versions
File nameFile versionFile sizeDateTimePlatform
For all supported x64-based versions
File nameFile versionFile sizeDateTimePlatform

How to obtain help and support for this security update
Help for installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help for protecting your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

↑ Back to the top

Applies to

This article applies to the following:
  • Microsoft .NET Framework 4.6 and 4.6.1 when used with:
    • Windows Server 2012 R2
    • Windows 8.1
    • Windows Server 2012

↑ Back to the top

Keywords: kbsecvulnerability, kbsecurity, kbsecbulletin, kbmustloc, kblangall, kbfix, kbexpertiseinter, kbbug, atdownload, kb, kbsecreview

↑ Back to the top

Article Info
Article ID : 3164024
Revision : 3
Created on : 4/13/2020
Published on : 4/16/2020
Exists online : False
Views : 234