1.    13 Sep 2017 #1
    Join Date : Oct 2013
    Posts : 25,174
    64-bit Windows 10 Pro build 17040

    .NET Framework September 2017 Security and Quality Rollup


    Today, we are releasing the September 2017 Security and Quality Rollup and Security Only Update.This update applies to Windows 7 and later client versions and Windows Server 2008 and later server versions.

    Security

    This release contains the following security changes.

    CVE-2017-8759 | .NET Framework Remote Code Execution Vulnerability

    A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input. An attacker who successfully exploited this vulnerability in software using the .NET framework could take control of an affected system. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

    To exploit the vulnerability, an attacker would first need to convince the user to open a malicious document or application.

    The security update addresses the vulnerability by correcting how .NET validates untrusted input.

    More Information: CVE-2017-8759

    Quality and Reliability

    This release contains the following quality and reliability improvements.

    ASP.NET

    • Values added to System.Web.Cache expire immediately, with .NET Framework 4.7. [452228]
    • ASP.NET site running on Sitefinity broken, with .NET Framework 4.7. [457739]

    CLR

    • CRWLock::StaticAcquireWriterLock() never returns if Int32.MaxValue number of ReaderWriterLock objects are created, with .NET Framework 3.5. [242568]
    • Crash in CLR assembly metadata reader. [367294]
    • .NET remoting IPC listener thread exits and leaves an orphaned IPCServerchannel. [454409]
    • Silent bad codegen when optimizing expression. [460765]
    • Crash in Visual Studio due to race in CLR assembly loader. [462762]
    • Runtime underallocates arrays by one element in rare cases when jitting large methods. [463604]
    • AppContext feature opt-in/out not functioning correctly. [469020]

    Management

    • Reboot method of Win32_OperatingSystem has Privilege not held exception [441901]

    Networking

    • HTTPWebRequest times out when switching to TLS after installing update KB4019112. [465796]

    WCF

    • NetTcp with X509Certificates using SslStream uses the default TLS version as the OS, with .NET Framework 4.7. [451528]

    Windows Forms

    • Excessive object creation in a performance-critical code-path leading to performance regressions and/or displaying empty UI and/or exhausting GDI+ handles. [452048]
    • Multi-Mon support: Controls with non-default anchoring are moved around the screen when scaling is changed [462872].
      • Note: This fix will be made available for Windows 10 1607 (Anniversary Update) in October.

    WPF

    • WPF fails to load resources if two versions of the same assembly are loaded. [378607]
      • Note: This fix will be made available for Windows 10 1703 (Creators Update) in October.
    • WPF consumes high % of CPU in Visual Studio when console session not active. [391184]
      • Note: This fix will be made available for Windows 10 in October.

    • Visual Studio fails due to “Unable to load DLL ‘PenIMC.dll’” error. [452476]
      • Note: This fix will be made available for Windows 10 1703 (Creators Update) in October.
    • Application crash due to call into DWrite. [453529]
      • Note: This fix will be made available for Windows 10 in October.
    • TargetFrameworkName is null with mixed mode application. [425074]
      • Note: This fix will be made available for Windows 10 1703 (Creators Update) in October.
    • Event leak with WPF application on touch screen monitors on Windows 10. [434946]
      • Note: This fix will be made available for Windows 10 1703 (Creators Update) in October.

    Note: Fixes are not always available for all Windows versions at the same time. This situation is noted where appropriate, and where the information is available, a release date is provided.

    Note: Additional information on these improvements is not available. The VSTS bug number provided with each improvement is a unique ID that you can give Microsoft Customer Support, include in StackOverflow commentsor use in web searches.

    Getting the Update

    The Security and Quality Rollup is available via Windows Update, Windows Server Update Services, Microsoft Update Catalog, and Docker.

    Microsoft Update Catalog

    You can get the update via the Microsoft Update Catalog. For Windows 10, .NET Framework updates are part of the Windows 10 Monthly Rollup.

    Product Version Security and Quality Rollup KB Security Rollup KB
    Windows 10 1703 (Creators Update) Catalog
    4038788
    N/A
    .NET Framework 4.7 4038788 N/A
    .NET Framework 3.5 4038788 N/A
    Windows 10 1607 (Anniversary Update)
    Windows Server 2016
    Catalog
    4038782
    N/A
    .NET Framework 4.6.2, 4.7 4038782 N/A
    .NET Framework 3.5 4038782 N/A
    Windows 10 1511 Catalog
    4038783
    N/A
    .NET Framework 4.6.1 4038783 N/A
    .NET Framework 3.5 4038783 N/A
    Windows 10 1507 Catalog
    4038781
    N/A
    .NET Framework 4.6 4038781 N/A
    .NET Framework 3.5 4038781 N/A
    Windows 8.1
    Windows RT 8.1
    Windows Server 2012 R2
    Catalog
    4041085
    Catalog
    4041092
    .NET Framework 3.5 4040981 4040967
    .NET Framework 4.5.2 4040974 4040958
    .NET Framework 4.6, 4.6.1, 4.6.2, 4.7 4040972 4040956
    Windows Server 2012 Catalog
    4041084
    Catalog
    4041091
    .NET Framework 3.5 4040979 4040965
    .NET Framework 4.5.2 4040975 4040959
    .NET Framework 4.6 4040971 4040955
    Windows 7
    Windows Server 2008 R2
    Catalog
    4041083
    Catalog
    4041090
    .NET Framework 3.5.1 4040980 4040966
    .NET Framework 4.5.2 4040977 4040960
    .NET Framework 4.6, 4.6.1, 4.6.2, 4.7 4040973 4040957
    Windows Server 2008 Catalog
    4041086
    Catalog
    4041093
    .NET Framework 2.0 4040978 4040964
    .NET Framework 4.5.2 4040977 4040960
    .NET Framework 4.6 4040973 4040957

    Docker Images

    Docker images has not yet been updated as part of today’s release. They will be updated in the shortly. This post will be updated at that time.


    Source: .NET Framework September 2017 Security and Quality Rollup | .NET Blog
    Last edited by Brink; 13 Sep 2017 at 11:52.
      My ComputersSystem Spec
  2.    21 Sep 2017 #2
    Join Date : Oct 2013
    Posts : 25,174
    64-bit Windows 10 Pro build 17040
    Thread Starter
      My ComputersSystem Spec

 


Similar Threads
Thread Forum
.NET Framework August 2017 Security and Quality Rollup
Source: .NET Framework August 2017 Security and Quality Rollup | .NET Blog
Windows 10 News
.NET Framework July 2017 Preview of Quality Rollup
Source: .NET Framework July 2017 Preview of Quality Rollup | .NET Blog
Windows 10 News
.NET Framework July 2017 Security and Quality Rollup
Source: .NET Framework July 2017 Security and Quality Rollup | .NET Blog
Windows 10 News
.NET Framework May 2017 Preview of Quality Rollup
Source: .NET Framework May 2017 Preview of Quality Rollup | .NET Blog
Windows 10 News
.NET Framework May 2017 Monthly Rollup
Source: .NET Framework May 2017 Monthly Rollup | .NET Blog
Windows 10 News
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 23:51.
Find Us
Twitter Facebook Google+ Ten Forums iOS App Ten Forums Android App



Windows 10 Forums