Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Security Only Update for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2 for Windows 7 SP1 and Server 2008 R2 SP1 and .NET Framework 4.6 for Server 2008 (KB4495587)


View products that this article applies to.

↑ Back to the top


Summary

Denial of service vulnerabilities exist when .NET Framework improperly handles objects in heap memory, or when .NET Framework and .NET Core improperly process RegEx strings.

To learn more about the vulnerabilities, go to the following Common Vulnerabilities and Exposures (CVE).

Important

  • All updates for .NET Framework 4.7.2, 4.7.1, 4.7, 4.6.2, 4.6.1, and 4.6 require that the d3dcompiler_47.dll update is installed. We recommend that you install the included d3dcompiler_47.dll update before you apply this update. For more information about the d3dcompiler_47.dll, see KB 4019990.
  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.

↑ Back to the top


Additional information about this update

For more information about this update as it relates to its particular Windows version(s), see the following article(s) in the Microsoft Knowledge Base:.
  • 4498961 Security Only Update for .NET Framework 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8 for Windows 7 SP1 and Server 2008 R2 SP1 (KB4498961)
  • 4498964 Security Only Update for .NET Framework 2.0, 3.0, 4.5.2, 4.6, 4.8 for Windows Server 2008 SP2 (KB4498964)

↑ Back to the top


How to obtain and install the update

Method 1: Microsoft Update Catalog

To get the standalone package for this update, go to the Microsoft Update Catalog.

Method 2: Windows Software Update Services (WSUS)

On your WSUS server, follow these steps:

  1. Select Start, select Administrative Tools, and then select Microsoft Windows Server Update Services 3.0.
  2. Expand ComputerName, and then select Action.
  3. Select Import Updates.
  4. WSUS opens a browser window in which you may be prompted to install an ActiveX control. You must install the ActiveX control to continue.
  5. After the ActiveX control is installed, you see the Microsoft Update Catalog screen. Type 4498961 for Windows 7 SP1 and Server 2008 R2 SP1 or type 4498964 for Windows Server 2008 SP2 in the Search box, and then select Search. 
  6. Locate the .NET Framework packages that match the operating systems, languages, and processors in your environment. Select Add to add them to your basket.
  7. After you select all the packages that you require, select View Basket.
  8. To import the packages to your WSUS server, select Import.
  9. After the packages are imported, select Close to return to WSUS.

The updates are now available for installation through WSUS.

↑ Back to the top


Update deployment information

For deployment details for this security update, go to the following article in the Microsoft Knowledge Base:

20190514 Security update deployment information: February 12, 2019

Update removal information

Note We do not recommend that you remove any security update. To remove this update, use the Programs and Features item in Control Panel.

Update restart information

This update does not require a system restart after you apply it unless files that are being updated are locked or are being used.

Update replacement information

This update replaces previously released updates 4481481 and 4481487.

↑ Back to the top


File information

File hash information
File name SHA1 hash SHA256 hash
NDP46-KB4495587-x64.exe C57FCBD99402FB5C48379DCE2D08859D2F5C27B0 5785AE76C6BED14F5A0C12DE01698F65DC7D00E765E2D6915C36B0CF2B655AF1
NDP46-KB4495587-x86.exe C4172AD5803A4E71CA948C751BE9D339FED66CA3 05B97FE221BBDCE4B7A6CD920D3F1E71BE1AD352F9E822A5AEE8E0A2C2A01FEA

File information

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and the times for these files are listed in Coordinated Universal Time (UTC). The dates and the times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and the times may change when you perform certain operations on the files.

For all supported x64-based versions
File name File version File size Date Time
clr.dll 4.7.3416.0 10,377,776 10-Apr-2019 21:42
clr.dll 4.7.3416.0 7,249,456 10-Apr-2019 21:31
clrjit.dll 4.7.3416.0 1,221,680 10-Apr-2019 21:42
clrjit.dll 4.7.3416.0 522,800 10-Apr-2019 21:31
compatjit.dll 4.7.3416.0 1,259,568 10-Apr-2019 21:42
mscordacwks.dll 4.7.3416.0 1,840,176 10-Apr-2019 21:42
mscordacwks.dll 4.7.3416.0 1,343,016 10-Apr-2019 21:31
mscordbi.dll 4.7.3416.0 1,622,064 10-Apr-2019 21:42
mscordbi.dll 4.7.3416.0 1,168,936 10-Apr-2019 21:31
mscorlib.dll 4.7.3416.0 5,427,248 10-Apr-2019 21:42
mscorlib.dll 4.7.3416.0 5,645,360 10-Apr-2019 21:31
msvcp120_clr0400.dll 12.0.52519.0 690,008 10-Apr-2019 21:42
msvcp120_clr0400.dll 12.0.52519.0 485,576 10-Apr-2019 21:32
msvcr120_clr0400.dll 12.0.52519.0 993,632 10-Apr-2019 21:42
msvcr120_clr0400.dll 12.0.52519.0 987,840 10-Apr-2019 21:32
peverify.dll 4.7.3416.0 260,144 10-Apr-2019 21:42
peverify.dll 4.7.3416.0 188,696 10-Apr-2019 21:31
SOS.dll 4.7.3416.0 871,984 10-Apr-2019 21:42
SOS.dll 4.7.3416.0 743,688 10-Apr-2019 21:31
System.dll 4.7.3416.0 3,562,312 10-Apr-2019 21:31
For all supported x86-based versions
File name File version File size Date Time
clr.dll 4.7.3416.0 7,249,456 10-Apr-2019 21:31
clrjit.dll 4.7.3416.0 522,800 10-Apr-2019 21:31
mscordacwks.dll 4.7.3416.0 1,343,016 10-Apr-2019 21:31
mscordbi.dll 4.7.3416.0 1,168,936 10-Apr-2019 21:31
mscorlib.dll 4.7.3416.0 5,645,360 10-Apr-2019 21:31
msvcp120_clr0400.dll 12.0.52519.0 485,576 10-Apr-2019 21:32
msvcr120_clr0400.dll 12.0.52519.0 987,840 10-Apr-2019 21:32
peverify.dll 4.7.3416.0 188,696 10-Apr-2019 21:31
SOS.dll 4.7.3416.0 743,688 10-Apr-2019 21:31
System.dll 4.7.3416.0 3,562,312 10-Apr-2019 21:31

↑ Back to the top


Information about protection and security

↑ Back to the top


Keywords: kbsurveynew, kbSupportTopic, kbsecvulnerability, kbsecurity, kbsecreview, kbsecbulletin, kbmustloc, kbContentAuto, kbfix, kbexpertiseinter, Vulnerabilities/exploits/security bulletins, kbbug, kb, atdownload, kblangall

↑ Back to the top

Article Info
Article ID : 4495587
Revision : 22
Created on : 8/12/2019
Published on : 8/12/2019
Exists online : False
Views : 186