This update resolves a vulnerability in the Microsoft .NET Framework that could allow denial of service if an attacker sends a few specially crafted requests to an affected .NET-enabled website. By default, ASP.NET is not installed when the .NET Framework is installed on any supported edition of Windows. To be affected by the vulnerability, customers must manually install and enable ASP.NET by registering it with Internet Information Services (IIS).
Microsoft has released security bulletin MS14-053. Learn more about how to obtain the fixes that are included in this security bulletin:
- For individual, small business, and organizational users, use the Windows automatic updating feature to install the fixes from Microsoft Update. To do this, see Get security updates automatically on the Microsoft Safety and Security Center website.
- For IT professionals, see Microsoft Security Bulletin MS14-053 on the Security TechCenter website.
How to obtain help and support for this security updateHelp installing updates: Support for Microsoft Update
Security solutions for IT professionals: TechNet Security Troubleshooting and Support
Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center
Local support according to your country: International Support
More information about this security update
Restart informationThis update does not require a system restart after you apply it unless files that are being updated are locked or are being used.
Update replacement informationThis update does not replace any previously released update.
Update removal informationNote We do not recommend that you remove any security update.
To remove this update, use the Add or Remove Programs item in Control Panel.
Article ID: 2973115 - Last Review: Sep 9, 2014 - Revision: 1