MS16-091: Description of the security update for the .NET Framework 4.6 and 4.6.1 in Windows Server 2012: July 12, 2016

Attiecas uz: .NET Framework 4.6.1.NET Framework 4.6

November 8, 2016 A detection change was made to account for the .NET Framework 4.6.1 hotfix rollup for customers who were not being correctly offered this security update for the .NET Framework 4.6.1.


This update resolves a vulnerability in the Microsoft .NET Framework. The vulnerability could cause information disclosure if an attacker uploads a specially crafted XML file to a web-based application. To learn more about this vulnerability, see Microsoft Security Bulletin MS16-091.

How to obtain and install this update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to get security updates automatically, see the "Turn on automatic updating in the Control Panel" section of this Safety & Security Center article.

Method 2: Microsoft Download Center

You can obtain the stand-alone update package through the Microsoft Download Center. To install this update, follow the installation instructions on the download page.

Download Download security update 3164023

Update deployment information

For deployment information about this update, see Microsoft Knowledge Base Article 3170048 .

Update removal information

Note We do not recommend that you remove any security update.

To remove this update, use the Programs and Features item in Control Panel.

Update restart information

This update does not require a system restart after you apply it unless files that are being updated are locked or are being used.

Update replacement information

This update does not replace any previously released update.

Applies to

This article applies to the following:
  • Microsoft .NET Framework 4.6 and 4.6.1 when used with:
    • Windows Server 2012