This update resolves a vulnerability in the Microsoft .NET Framework that could allow information disclosure if an attacker sends a specially crafted web request to an affected server that has custom error messages disabled. An attacker who successfully exploits the vulnerability would be able to view parts of a web configuration file that could expose sensitive information.
Microsoft has released security bulletin MS15-041. Learn more about how to obtain the fixes that are included in this security bulletin:
- For individual, small business, and organizational users, use the Windows automatic updating feature to install the fixes from Microsoft Update. To do this, see Get security updates automatically on the Microsoft Safety and Security Center website.
- For IT professionals, see Microsoft Security Bulletin MS15-041 on the Security TechCenter website.
How to obtain help and support for this security updateHelp installing updates: Support for Microsoft Update
Security solutions for IT professionals: TechNet Security Troubleshooting and Support
Help protect your Windows-based computer from viruses and malware: Virus Solution and Security Center
Local support according to your country: International Support
More information about this security update
Restart informationThis update does not require a system restart after you apply it unless files that are being updated are locked or are being used.
Note This update will cause the IIS Service to restart.
Update replacement informationThis update replaces the following update:
2901110 MS14-009: Description of the security update for the .NET Framework 4 on Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2: February 11, 2014
Update removal informationNote We do not recommend that you remove any security update.
To remove this update, use the Programs and Features item in Control Panel.
Article ID: 3037578 - Last Review: Jul 17, 2015 - Revision: 1