This security update resolves an information disclosure vulnerability in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments. The vulnerability is caused when .NET Framework is used in high-load/high-density network connections where content from one stream can blend into another stream.
To exploit the vulnerability, an attacker who can access one tenant in a high-load/high-density environment could potentially trigger multi-tenanted data exposure from one customer to another.
This security update addresses the vulnerability by correcting the way .NET Framework handles high-load/high-density network connections.To learn more about this vulnerability, see Microsoft Common Vulnerabilities and Exposures CVE-2018-8360.
- If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.
Additional information about this security update
- 4344151 Description of the Security and Quality Rollup for .NET Framework 2.0 SP2 and 3.0 SP2 for Windows Server 2008 SP2 (KB 4344151)
- 4344149 Description of the Security and Quality Rollup for .NET Framework 4.5.2 for Windows 7 SP1, Server 2008 R2 SP1 and Server 2008 SP2 (KB 4344149)
- 4344146 Description of the Security and Quality Rollup for .NET Framework 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1 and 4.7.2 for Windows 7 SP1, Server 2008 R2 SP1 and for .NET Framework 4.6 for Server 2008 SP2 (KB 4344146)
How to obtain help and support for this security update
- Help for installing updates: Windows Update FAQ
- Security solutions for IT professionals: TechNet Security Support and Troubleshooting
- Help for protecting your Windows-based products and services from viruses and malware: Microsoft Secure
- Local support according to your country: International Support