MS16-120: Description of the Security and Quality Rollup for the .NET Framework 3.0 Service Pack 2, 4.5.2, and 4.6 for Windows Vista and Windows Server 2008: October 11, 2016

Notice
November 8, 2016: This Security and Quality Rollup for .NET Framework 3.0 Service Pack 2, 4.5.2, and 4.6 for Windows Vista and Windows Server 2008 has been re-released. This re-release addresses an issue in which supersedence detection, specifically in Windows Server Update Services (WSUS) environments where various updates applicable to Windows 7 Service Pack 1 and Windows Server 2008 R2 Service Pack 1 were incorrectly marked as being superseded. This re-release removes the supersedence metadata in WSUS environments for this Security and Quality Rollup update. This is a detection metadata change only. There are no changes to the update payload content.
Summary
This update resolves vulnerabilities in the Microsoft .NET Framework. The vulnerabilities could allow remote code execution if a user visits a specially crafted website or opens a specially crafted document. This update addresses the vulnerabilities by correcting how the Windows font library handles embedded fonts. To learn more about this vulnerability, see Microsoft Security Bulletin MS16-120.

Important This security update requires the Windows dwrite.dll component. Up-to-date Windows Vista SP2 and Windows Server 2008 SP2 systems are expected to have this component installed. If dwrite.dll is not present on a system, it can be downloaded here. Windows Update, WSUS, and Microsoft Update Catalog customers will receive the Windows dwrite.dll component through the 3078601 update as an automatic co-install, just in case it’s not already present.
Additional information about this security update
The following articles contain additional information about this security update as it relates to individual product versions. The articles may contain known issue information.

  • 3188735 MS16-120: Description of the security update for the .NET Framework 3.0 Service Pack 2 for Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2: October 11, 2016
  • 3189051 MS16-120: Description of the security update for the .NET Framework 4.5.2 for Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2: October 11, 2016
  • 3189052 MS16-120: Description of the security update for the .NET Framework 4.6 for Windows Vista Service Pack 2 and Windows Server 2008 Service Pack 2: October 11, 2016

How to obtain help and support for this security update

Help for installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help for protecting your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

Applies to

This article applies to the following:

  • Microsoft .NET Framework 4.6 when used with:

    • Windows Server 2008 Service Pack 2
    • Windows Vista Service Pack 2
  • Microsoft .NET Framework 4.5.2 when used with:

    • Windows Server 2008 Service Pack 2
    • Windows Vista Service Pack 2
  • Microsoft .NET Framework 3.0 Service Pack 2 when used with:

    • Windows Server 2008 Service Pack 2
    • Windows Vista Service Pack 2
Egenskaper

Artikel-id: 3188744 – senaste granskning 11/08/2016 22:32:00 – revision: 5.0

Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 3.0 Service Pack 2

  • kbsecvulnerability kbsecurity kbsecbulletin kbfix kbexpertiseinter kbbug atdownload KB3188744
Feedback