MS14-053: Description of the security update for the .NET Framework 4.5, the .NET Framework 4.5.1, and the .NET Framework 4.5.2 for Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows Server 2008 R2 SP1: September 9, 2014

Introduction
This update resolves a vulnerability in the Microsoft .NET Framework that could allow denial of service if an attacker sends a few specially crafted requests to an affected .NET-enabled website. By default, ASP.NET is not installed when the .NET Framework is installed on any supported edition of Windows. To be affected by the vulnerability, customers must manually install and enable ASP.NET by registering it with Internet Information Services (IIS).
Summary
Microsoft has released security bulletin MS14-053. Learn more about how to obtain the fixes that are included in this security bulletin: 

How to obtain help and support for this security update

Help installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

More information about this security update

Download information

To install this update, install it from Microsoft Windows Update.

Additionally, you can install this update from the Microsoft Download Center.

Command-line switches for this update

Learn about the various command-line switches that are supported by this .NET Framework update.

Restart information

This update does not require a system restart after you apply it unless files that are being updated are locked or are being used.

Update replacement information

This update does not replace any previously released update.

Update removal information

Note We do not recommend that you remove any security update.

To remove this update, use the Programs and Features item in Control Panel.

File information

The English (United States) version of this update installs files that have the attributes that are listed in the following tables. The dates and the times for these files are listed in Coordinated Universal Time (UTC). The dates and the times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and the times may change when you perform certain operations on the files.

For all supported x86-based versions of systems
File nameFile versionFile sizeDateTime
ServiceMonikerSupport.dll4.0.30319.3423428,35223-Jul-201417:56
SMDiagnostics.dll4.0.30319.3423464,66423-Jul-201407:13
System.Activities.dll4.0.30319.342341,574,06423-Jul-201407:13
System.IdentityModel.dll4.0.30319.342341,085,10423-Jul-201407:13
System.IdentityModel.Services.dll4.0.30319.34234199,89623-Jul-201407:13
System.Runtime.Serialization.dll4.0.30319.342341,050,84023-Jul-201407:13
System.ServiceModel.Channels.dll4.0.30319.34234158,92823-Jul-201407:13
System.ServiceModel.Discovery.dll4.0.30319.34234312,53623-Jul-201407:13
System.ServiceModel.dll4.0.30319.342346,371,50423-Jul-201407:13
System.ServiceModel.Internals.dll4.0.30319.34234245,97623-Jul-201407:13
System.ServiceModel.WasHosting.dll4.0.30319.3423439,64023-Jul-201417:56
System.Data.SqlXml.dll4.0.30319.34234743,59223-Jul-201407:13
System.Xml.dll4.0.30319.342342,694,28023-Jul-201407:13
msvcr120_clr0400.dll12.0.51674.34234875,68023-Jul-201417:56
For all supported x64-based versions of systems
File nameFile versionFile sizeDateTime
ServiceMonikerSupport.dll4.0.30319.3423428,85623-Jul-201418:14
ServiceMonikerSupport.dll4.0.30319.3423428,35223-Jul-201417:56
SMDiagnostics.dll4.0.30319.3423464,66423-Jul-201407:13
System.Activities.dll4.0.30319.342341,574,06423-Jul-201407:13
System.IdentityModel.dll4.0.30319.342341,085,10423-Jul-201407:13
System.IdentityModel.Services.dll4.0.30319.34234199,89623-Jul-201407:13
System.Runtime.Serialization.dll4.0.30319.342341,050,84023-Jul-201407:13
System.ServiceModel.Channels.dll4.0.30319.34234158,92823-Jul-201407:13
System.ServiceModel.Discovery.dll4.0.30319.34234312,53623-Jul-201407:13
System.ServiceModel.dll4.0.30319.342346,371,50423-Jul-201407:13
System.ServiceModel.Internals.dll4.0.30319.34234245,97623-Jul-201407:13
System.ServiceModel.WasHosting.dll4.0.30319.3423439,64023-Jul-201417:56
System.Data.SqlXml.dll4.0.30319.34234743,59223-Jul-201407:13
System.XML.dll4.0.30319.342342,694,28023-Jul-201407:13
msvcr120_clr0400.dll12.0.51674.34234869,53623-Jul-201418:14
msvcr120_clr0400.dll12.0.51674.34234875,68023-Jul-201417:56

Applies to

This article applies to the following:
  • The Microsoft .NET Framework 4.5.2 when used with:
    • Windows 7 Service Pack 1
    • Windows Server 2008 R2 Service Pack 1
    • Windows Vista Service Pack 2
    • Windows Server 2008 Service Pack 2
  • The Microsoft .NET Framework 4.5.1 when used with:
    • Windows 7 Service Pack 1
    • Windows Server 2008 R2 Service Pack 1
    • Windows Vista Service Pack 2
    • Windows Server 2008 Service Pack 2
  • The Microsoft .NET Framework 4.5 when used with:
    • Windows 7 Service Pack 1
    • Windows Server 2008 R2 Service Pack 1
    • Windows Vista Service Pack 2
    • Windows Server 2008 Service Pack 2
Properties

Article ID: 2972216 - Last Review: 09/09/2014 17:18:00 - Revision: 1.0

  • kbsecvulnerability kbsecurity kbsecbulletin kbfix kbexpertiseinter kbbug atdownload KB2972216
Feedback