MS15-041: Vulnerability in the .NET Framework could allow information disclosure: April 14, 2015

Applies to: .NET Framework 4.5.NET Framework 3.5.1

Introduction


This update resolves a vulnerability in the Microsoft .NET Framework that could allow information disclosure if an attacker sends a specially crafted web request to an affected server that has custom error messages disabled. An attacker who successfully exploits the vulnerability would be able to view parts of a web configuration file that could expose sensitive information.

Summary


Microsoft has released security bulletin MS15-041. Learn more about how to obtain the fixes that are included in this security bulletin:

How to obtain help and support for this security update

Help installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help protect your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

More Information


Additional information about this update

The following articles contain additional information about this update as it relates to individual product versions. The articles may contain specific information to the individual updates such as download URL, prerequisites, and command-line switches.
Microsoft .NET Framework 4.5, 4.5.1, and 4.5.2
  • 3037581 MS15-041: Description of the security update for the .NET Framework 4.5, 4.5.1, and 4.5.2 on Windows Vista Service Pack 2, Windows Server 2008 Service Pack 2, Windows 7 Service Pack 1, and Windows Server 2008 R2 Service Pack 1: April 14, 2015
  • 3037580 MS15-041: Description of the security update for the .NET Framework 4.5, 4.5.1, and 4.5.2 on Windows 8, Windows RT, and Windows Server 2012: April 14, 2015
  • 3037579 MS15-041: Description of the security update for the .NET Framework 4.5.1 and 4.5.2 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2: April 14, 2015

Microsoft .NET Framework 4
  • 3037578 MS15-041: Description of the security update for the .NET Framework 4 on Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2: April 14, 2015

Microsoft .NET Framework 3.5.1
  • 3037574 MS15-041: Description of the security update for the .NET Framework 3.5.1 on Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1: April 14, 2015

Microsoft .NET Framework 3.5
  • 3037576 MS15-041: Description of the security update for the .NET Framework 3.5 on Windows 8.1 and Windows Server 2012 R2: April 14, 2015
  • 3037575 MS15-041: Description of the security update for the .NET Framework 3.5 on Windows 8 and Windows Server 2012: April 14, 2015

Microsoft .NET Framework 2.0
  • 3037573 MS15-041: Description of the security update for the .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2: April 14, 2015
  • 3037577 MS15-041: Description of the security update for the .NET Framework 2.0 Service Pack 2 on Windows Server 2003: April 14, 2015
Microsoft .NET Framework 1.1
  • 3037572 MS15-041: Description of the security update for the .NET Framework 1.1 Service Pack 1 on x86-based versions of Windows Server 2003 Service Pack 2: April 14, 2015

Update replacement information

Update replacement information for each specific update can be found in the Knowledge Base articles that correspond to this update.

Applies to

This article applies to the following:
  • Microsoft .NET Framework 4.5.2 when used with:
    • Windows Server 2012 R2
    • Windows 8.1
    • Windows RT 8.1
    • Windows Server 2012
    • Windows 8
    • Windows RT
    • Windows Server 2008 R2 Service Pack 1
    • Windows 7 Service Pack 1
    • Windows Server 2008 Service Pack 2
    • Windows Vista Service Pack 2
  • Microsoft .NET Framework 4.5.1 when used with:
    • Windows Server 2012 R2
    • Windows 8.1
    • Windows RT 8.1
    • Windows Server 2012
    • Windows 8
    • Windows RT
    • Windows Server 2008 R2 Service Pack 1
    • Windows 7 Service Pack 1
    • Windows Server 2008 Service Pack 2
    • Windows Vista Service Pack 2
  • Microsoft .NET Framework 4.5 when used with:
    • Windows Server 2012
    • Windows 8
    • Windows RT
    • Windows Server 2008 R2 Service Pack 1
    • Windows 7 Service Pack 1
    • Windows Server 2008 Service Pack 2
    • Windows Vista Service Pack 2
  • Microsoft .NET Framework 4 when used with:
    • Windows Server 2008 R2 Service Pack 1
    • Windows 7 Service Pack 1
    • Windows Server 2008 Service Pack 2
    • Windows Vista Service Pack 2
    • Windows Server 2003 Service Pack 2
  • Microsoft .NET Framework 3.5.1 when used with:
    • Windows Server 2008 R2 Service Pack 1
    • Windows 7 Service Pack 1
  • Microsoft .NET Framework 3.5 when used with:
    • Windows Server 2012 R2
    • Windows 8.1
    • Windows Server 2012
    • Windows 8
  • Microsoft .NET Framework 2.0 Service Pack 2 when used with:
    • Windows Server 2008 Service Pack 2
    • Windows Vista Service Pack 2
    • Windows Server 2003 Service Pack 2
  • Microsoft .NET Framework 1.1 Service Pack 1 when used with:
    • Windows Server 2003 Service Pack 2