{"id":20684,"date":"2018-12-11T10:23:48","date_gmt":"2018-12-11T18:23:48","guid":{"rendered":"https:\/\/blogs.msdn.microsoft.com\/dotnet\/?p=20585"},"modified":"2019-02-19T18:40:37","modified_gmt":"2019-02-20T01:40:37","slug":"net-framework-december-2018-security-and-quality-rollup","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/dotnet\/net-framework-december-2018-security-and-quality-rollup\/","title":{"rendered":".NET Framework December 2018 Security and Quality Rollup"},"content":{"rendered":"<p>Today, we are releasing the December 2018 Security and Quality Rollup.<\/p>\n<h2><a href=\"#security\" id=\"user-content-security\" class=\"anchor\"><\/a>Security<\/h2>\n<h3><a href=\"#cve-2018-8540--windows-security-feature-bypass-vulnerability\" id=\"user-content-cve-2018-8540--windows-security-feature-bypass-vulnerability\" class=\"anchor\"><\/a>CVE-2018-8540 \u2013 Windows Remote Code Execution Vulnerability<\/h3>\n<p><span>This security update resolves a vulnerability in Microsoft .NET Framework that could allow remote code execution when Microsoft .NET Framework doesn&#8217;t validate input correctly. The\u00a0attacker who successfully exploits\u00a0this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts that use full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who are granted administrative user rights.<\/span><\/p>\n<div class=\"ng-scope\" role=\"presentation\">\n<article class=\"ng-scope\" role=\"article\">\n<div class=\"ng-scope\">\n<div class=\"article-container\">\n<div class=\"ng-scope ng-isolate-scope\">\n<div class=\"main-content-container\">\n<div class=\"content-article\">\n<div class=\"ng-isolate-scope\">\n<div class=\"ng-scope\">\n<div class=\"ng-isolate-scope\">\n<section class=\"section ng-scope\">\n<div class=\"section-body ng-scope\">\n<div class=\"ng-scope\">\n<div class=\"ng-isolate-scope\">\n<div class=\"kb-summary-section section ng-scope\">\n<p><span>To exploit the vulnerability, an attacker has to pass specific input to an application that uses susceptible .NET Framework methods.<\/span><\/p>\n<p><span>This security update addresses the vulnerability by correcting how .NET Framework validates input.<\/span><\/p>\n<\/div>\n<p><span>To learn more about this vulnerability, see\u00a0<a target=\"_blank\" href=\"https:\/\/portal.msrc.microsoft.com\/security-guidance\/advisory\/CVE-2018-8540\" rel=\"noopener\" id=\"kb-link-2\" class=\"managed-link content-anchor-link\">Microsoft Common Vulnerabilities and Exposures CVE-2018-8540<\/a>.<\/span><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/article>\n<\/div>\n<h2><a href=\"#getting-the-update\" id=\"user-content-getting-the-update\" class=\"anchor\"><\/a>Getting the Update<\/h2>\n<p>The Security and Quality Rollup is available via Windows Update, Windows Server Update Services, Microsoft Update Catalog, and Docker.<\/p>\n<h3><a href=\"#microsoft-update-catalog\" id=\"user-content-microsoft-update-catalog\" class=\"anchor\"><\/a>Microsoft Update Catalog<\/h3>\n<p>You can get the update via the Microsoft Update Catalog. For Windows 10, .NET Framework updates are part of the Windows 10 Monthly Rollup.<\/p>\n<p>The following table is for Windows 10 and Windows Server 2016+.<\/p>\n<table>\n<thead>\n<tr>\n<th>Product Version<\/th>\n<th>Security and Quality Rollup KB<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Windows 10 1809 (October 2018 Update)\nWindows Server 2019<\/strong><\/td>\n<td><strong><a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=4470502\" rel=\"nofollow\">Catalog<\/a>\n<a href=\"https:\/\/support.microsoft.com\/kb\/4470502\" rel=\"nofollow\">4470502<\/a><\/strong><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 3.5<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470502\" rel=\"nofollow\">4470502<\/a><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 4.7.2<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470502\" rel=\"nofollow\">4470502<\/a><\/td>\n<\/tr>\n<tr><\/tr>\n<tr>\n<td><strong>Windows 10 1803 (April 2018 Update)<\/strong><\/td>\n<td><strong><a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=4471324\" rel=\"nofollow\">Catalog<\/a>\n<a href=\"https:\/\/support.microsoft.com\/kb\/4471324\" rel=\"nofollow\">4471324<\/a><\/strong><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 3.5<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4471324\" rel=\"nofollow\">4471324<\/a><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 4.7.2<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4471324\" rel=\"nofollow\">4471324<\/a><\/td>\n<\/tr>\n<tr>\n<td><strong>Windows 10 1709 (Fall Creators Update)<\/strong><\/td>\n<td><strong><a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=4471329\" rel=\"nofollow\">Catalog<\/a>\n<a href=\"https:\/\/support.microsoft.com\/kb\/4471329\" rel=\"nofollow\">4471329<\/a><\/strong><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 3.5<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4471329\" rel=\"nofollow\">4471329<\/a><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 4.7.1, 4.7.2<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4471329\" rel=\"nofollow\">4471329<\/a><\/td>\n<\/tr>\n<tr>\n<td><strong>Windows 10 1703 (Creators Update)<\/strong><\/td>\n<td><strong><a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=4471327\" rel=\"nofollow\">Catalog<\/a>\n<a href=\"https:\/\/support.microsoft.com\/kb\/4471327\" rel=\"nofollow\">4471327<\/a><\/strong><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 3.5<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4471327\" rel=\"nofollow\">4471327<\/a><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 4.7, 4.7.1, 4.7.2<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4471327\" rel=\"nofollow\">4471327<\/a><\/td>\n<\/tr>\n<tr>\n<td><strong>Windows 10 1607 (Anniversary Update)\nWindows Server 2016<\/strong><\/td>\n<td><strong><a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=4471321\" rel=\"nofollow\">Catalog<\/a>\n<a href=\"https:\/\/support.microsoft.com\/kb\/4471321\" rel=\"nofollow\">4471321<\/a><\/strong><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 3.5<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4471321\" rel=\"nofollow\">4471321<\/a><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 4.6.2, 4.7, 4.7.1, 4.7.2<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4471321\" rel=\"nofollow\">4471321<\/a><\/td>\n<\/tr>\n<tr>\n<td><strong>Windows 10 1507<\/strong><\/td>\n<td><strong><a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=4471323\" rel=\"nofollow\">Catalog<\/a>\n<a href=\"https:\/\/support.microsoft.com\/kb\/4471323\" rel=\"nofollow\">4471323<\/a><\/strong><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 3.5<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4471323\" rel=\"nofollow\">4471323<\/a><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 4.6, 4.6.1, 4.6.2<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4471323\" rel=\"nofollow\">4471323<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The following table is for earlier Windows and Windows Server versions.<\/p>\n<table>\n<thead>\n<tr>\n<th>Product Version<\/th>\n<th>Security and Quality Rollup KB<\/th>\n<th>Security Only Update KB<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Windows 8.1\nWindows RT 8.1\nWindows Server 2012 R2<\/strong><\/td>\n<td><strong><a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=4471989\" rel=\"nofollow\">Catalog<\/a>\n<a href=\"https:\/\/support.microsoft.com\/kb\/4471989\" rel=\"nofollow\">4471989<\/a><\/strong><\/td>\n<td><strong><a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=4471983\" rel=\"nofollow\">Catalog<\/a>\n<a href=\"https:\/\/support.microsoft.com\/kb\/4471983\" rel=\"nofollow\">4471983<\/a><\/strong><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 3.5<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470630\" rel=\"nofollow\">4470630<\/a><\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470602\" rel=\"nofollow\">4470602<\/a><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 4.5.2<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470622\" rel=\"nofollow\">4470622<\/a><\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470491\" rel=\"nofollow\">4470491<\/a><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470639\" rel=\"nofollow\">4470639<\/a><\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470499\" rel=\"nofollow\">4470499<\/a><\/td>\n<\/tr>\n<tr>\n<td><strong>Windows Server 2012<\/strong><\/td>\n<td><strong><a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=4471988\" rel=\"nofollow\">Catalog<\/a>\n<a href=\"https:\/\/support.microsoft.com\/kb\/4471988\" rel=\"nofollow\">4471988<\/a><\/strong><\/td>\n<td><strong><a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=4471982\" rel=\"nofollow\">Catalog<\/a>\n<a href=\"https:\/\/support.microsoft.com\/kb\/4471982\" rel=\"nofollow\">4471982<\/a><\/strong><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 3.5<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470629\" rel=\"nofollow\">4470629<\/a><\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470601\" rel=\"nofollow\">4470601<\/a><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 4.5.2<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470623\" rel=\"nofollow\">4470623<\/a><\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470492\" rel=\"nofollow\">4470492<\/a><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470638\" rel=\"nofollow\">4470638<\/a><\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470498\" rel=\"nofollow\">4470498<\/a><\/td>\n<\/tr>\n<tr>\n<td><strong>Windows 7\nWindows Server 2008 R2<\/strong><\/td>\n<td><strong><a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=4471987\" rel=\"nofollow\">Catalog<\/a>\n<a href=\"https:\/\/support.microsoft.com\/kb\/4471987\" rel=\"nofollow\">4471987<\/a><\/strong><\/td>\n<td><strong><a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=4471981\" rel=\"nofollow\">Catalog<\/a>\n<a href=\"https:\/\/support.microsoft.com\/kb\/4471981\" rel=\"nofollow\">4471981<\/a><\/strong><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 3.5.1<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470641\" rel=\"nofollow\">4470641<\/a><\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470600\" rel=\"nofollow\">4470600<\/a><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 4.5.2<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470637\" rel=\"nofollow\">4470637<\/a><\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470493\" rel=\"nofollow\">4470493<\/a><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, 4.7.2<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470640\" rel=\"nofollow\">4470640<\/a><\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470500\" rel=\"nofollow\">4470500<\/a><\/td>\n<\/tr>\n<tr>\n<td><strong>Windows Server 2008<\/strong><\/td>\n<td><strong><a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=4471990\" rel=\"nofollow\">Catalog<\/a>\n<a href=\"https:\/\/support.microsoft.com\/kb\/4471990\" rel=\"nofollow\">4471990<\/a><\/strong><\/td>\n<td><strong><a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=4471984\" rel=\"nofollow\">Catalog<\/a>\n<a href=\"https:\/\/support.microsoft.com\/kb\/4471984\" rel=\"nofollow\">4471984<\/a><\/strong><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 3.5 SP1<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4471102\" rel=\"nofollow\">4471102<\/a><\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470633\" rel=\"nofollow\">4470633<\/a><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 4.5.2<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470637\" rel=\"nofollow\">4470637<\/a><\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470493\" rel=\"nofollow\">4470493<\/a><\/td>\n<\/tr>\n<tr>\n<td>.NET Framework 4.6<\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470640\" rel=\"nofollow\">4470640<\/a><\/td>\n<td><a href=\"https:\/\/support.microsoft.com\/kb\/4470500\" rel=\"nofollow\">4470500<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3><a href=\"#docker-images\" id=\"user-content-docker-images\" class=\"anchor\"><\/a>Docker Images<\/h3>\n<p>We are updating the following .NET Framework Docker images for today\u2019s release:<\/p>\n<ul>\n<li><a href=\"https:\/\/hub.docker.com\/r\/microsoft\/aspnet\/\" rel=\"nofollow\">microsoft\/aspnet<\/a><\/li>\n<li><a href=\"https:\/\/hub.docker.com\/r\/microsoft\/dotnet-framework\/\" rel=\"nofollow\">microsoft\/dotnet-framework<\/a><\/li>\n<li><a href=\"https:\/\/hub.docker.com\/r\/microsoft\/dotnet-framework-samples\/\" rel=\"nofollow\">microsoft\/dotnet-framework-samples<\/a><\/li>\n<\/ul>\n<p>Note: Look at the \u201cTags\u201d view in each repository to see the updated Docker image tags.<\/p>\n<h3><a href=\"#previous-monthly-rollups\" id=\"user-content-previous-monthly-rollups\" class=\"anchor\"><\/a>Previous Monthly Rollups<\/h3>\n<p>The last few .NET Framework Monthly updates are listed below for your convenience:<\/p>\n<ul>\n<li><a href=\"https:\/\/blogs.msdn.microsoft.com\/dotnet\/2018\/12\/05\/net-framework-december-4-2018-preview-of-cumulative-update-for-windows-10-version-1809-and-windows-server-2019\/\" rel=\"nofollow\">November 2018 Preview of Cumulative Update for Windows 10 version 1809 and Windows Server 2019<\/a><\/li>\n<li><a href=\"https:\/\/blogs.msdn.microsoft.com\/dotnet\/2018\/11\/27\/net-framework-november-2018-preview-of-quality-rollup\/\" rel=\"nofollow\">November 2018 Preview of Quality Rollup<\/a><\/li>\n<li><a href=\"https:\/\/blogs.msdn.microsoft.com\/dotnet\/2018\/11\/13\/net-framework-november-2018-security-and-quality-rollup\/\" rel=\"nofollow\">November 2018 Security and Quality Rollup<\/a><\/li>\n<li><a href=\"https:\/\/blogs.msdn.microsoft.com\/dotnet\/2018\/10\/18\/net-framework-october-2018-preview-of-quality-rollup\/\" rel=\"nofollow\">October 2018 Preview of Quality Rollup<\/a><\/li>\n<li><a href=\"https:\/\/blogs.msdn.microsoft.com\/dotnet\/2018\/10\/09\/net-framework-october-2018-security-and-quality-rollup\/\" rel=\"nofollow\">October 2018 Security and Quality Rollup<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Today, we are releasing the December 2018 Security and Quality Rollup. Security CVE-2018-8540 \u2013 Windows Remote Code Execution Vulnerability This security update resolves a vulnerability in Microsoft .NET Framework that could allow remote code execution when Microsoft .NET Framework doesn&#8217;t validate input correctly. The\u00a0attacker who successfully exploits\u00a0this vulnerability could take control of an affected system. [&hellip;]<\/p>\n","protected":false},"author":369,"featured_media":21755,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[685,195,326],"tags":[4,11,123],"class_list":["post-20684","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-dotnet","category-dotnet-framework","category-security","tag-net","tag-net-framework","tag-security"],"acf":[],"blog_post_summary":"<p>Today, we are releasing the December 2018 Security and Quality Rollup. Security CVE-2018-8540 \u2013 Windows Remote Code Execution Vulnerability This security update resolves a vulnerability in Microsoft .NET Framework that could allow remote code execution when Microsoft .NET Framework doesn&#8217;t validate input correctly. The\u00a0attacker who successfully exploits\u00a0this vulnerability could take control of an affected system. [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/posts\/20684","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/users\/369"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/comments?post=20684"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/posts\/20684\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/media\/21755"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/media?parent=20684"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/categories?post=20684"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/dotnet\/wp-json\/wp\/v2\/tags?post=20684"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}