.NET Framework September 2023 Security and Quality Rollup Updates

Salini Agarwal

Today, we are releasing the September 2023 Security and Quality Rollup Updates for .NET Framework.

Security

CVE-2023-36796 – .NET Framework Remote Code Execution Vulnerability

This security update addresses a vulnerability in DiaSymReader.dll when reading a corrupted PDB file which can lead to Remote Code Execution.

CVE-2023-36792 – .NET Framework Remote Code Execution Vulnerability

This security update addresses a vulnerability in DiaSymReader.dll when reading a corrupted PDB file which can lead to Remote Code Execution.

CVE-2023-36793 – .NET Framework Remote Code Execution Vulnerability

This security update addresses a vulnerability in DiaSymReader.dll when reading a corrupted PDB file which can lead to Remote Code Execution.

CVE-2023-36794 – .NET Framework Remote Code Execution Vulnerability

This security update addresses a vulnerability in DiaSymReader.dll when reading a corrupted PDB file which can lead to Remote Code Execution.

CVE-2023-36788 – .NET Framework Remote Code Execution Vulnerability

This security update addresses a vulnerability in the WPF XAML parser where an unsandboxed parser can lead to remote code execution.

Quality and Reliability

This release contains the following quality and reliability improvements.

Windows Presentation Foundation (WPF)
  • Addresses an issue where the layout of collapsed panels are affected by CollectionChanged event.
Runtime
  • Addresses an issue where unpredictable crashes which could occur in multi-appdomain scenarios running on arm64.
  • Addresses an issue where AnchorInfo was miscalculated hen controls scaled on higher DPI settings and thus location may be calculated incorrect.
ASP.NET
  • Addresses an issue in the AspNetEnforceViewStateMac regkey logic.

Getting the Update

The Security and Quality Rollup is available via Windows Update, Windows Server Update Services, and Microsoft Update Catalog.

Note: Customers that rely on Windows Update and Windows Server Update Services will automatically receive the .NET Framework version-specific updates. Advanced system administrators can also take use of the below direct Microsoft Update Catalog download links to .NET Framework-specific updates. Before applying these updates, please ensure that you carefully review the .NET Framework version applicability, to ensure that you only install updates on systems where they apply.

The following table is for Windows 10, version 1507 and Windows Server 2016 versions and newer operating systems.

The following table is for Windows 10 and Windows Server 2016+ versions.

Product Version Cumulative Update
Windows 11, version 22H2 5031217
.NET Framework 3.5, 4.8.1 Catalog 5029921
Windows 11, version 21H2 5030181
.NET Framework 3.5, 4.8 Catalog 5029926
.NET Framework 3.5, 4.8.1 Catalog 5029920
Microsoft server operating system, version 22H2 5030177
.NET Framework 3.5, 4.8 Catalog 5029928
Microsoft server operating system version 21H2 5030186
.NET Framework 3.5, 4.8 Catalog 5029928
.NET Framework 3.5, 4.8.1 Catalog 5029922
Windows 10, version 22H2 5030180
.NET Framework 3.5, 4.8 Catalog 5029923
.NET Framework 3.5, 4.8.1 Catalog 5029919
Windows 10, version 21H2 5030179
.NET Framework 3.5, 4.8 Catalog 5029923
.NET Framework 3.5, 4.8.1 Catalog 5029919
Windows 10 1809 (October 2018 Update) and Windows Server 2019 5030178
.NET Framework 3.5, 4.7.2 Catalog 5029931
.NET Framework 3.5, 4.8 Catalog 5029925
Windows 10 1607 (Anniversary Update) and Windows Server 2016
.NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2 Catalog 5030213
.NET Framework 4.8 Catalog 5029924
Windows 10 1507
.NET Framework 3.5, 4.6, 4.6.2 Catalog 5030220

The following table is for earlier Windows and Windows Server versions.

Product Version Security and Quality Rollup Security Only Update
Windows Server 2012 R2 5030184 5030175
.NET Framework 3.5 Catalog 5029915 Catalog 5029940
.NET Framework 4.6.2, 4.7, 4.7.1, 4.7.2 Catalog 5029916 Catalog 5029941
.NET Framework 4.8 Catalog 5029917 Catalog 5029942
Windows Server 2012 5030183 5030174
.NET Framework 3.5 Catalog 5030160 Catalog 5030030
.NET Framework 4.6.2, 4.7, 4.7.1, 4.7.2 Catalog 5029932 Catalog 5029945
.NET Framework 4.8 Catalog 5029927 Catalog 5029943
Windows Embedded 7 and Windows Server 2008 R2 SP1 5030182 5030173
.NET Framework 3.5.1 Catalog 5029938 Catalog 5029948
.NET Framework 4.6.2, 4.7, 4.7.1, 4.7.2 Catalog 5029933 Catalog 5029946
.NET Framework 4.8 Catalog 5029929 Catalog 5029944
Windows Server 2008 5030185 5030176
.NET Framework 2.0, 3.0 Catalog 5029937 Catalog 5029947
.NET Framework 4.6.2 Catalog 5029933 Catalog 5029946

 

Previous Monthly Rollups

The last few .NET Framework Monthly updates are listed below for your convenience:

0 comments

Discussion is closed.

Feedback usabilla icon