.NET Framework December 2018 Security and Quality Rollup

    .NET Framework December 2018 Security and Quality Rollup


    Posted: 12 Dec 2018
    Today, we are releasing the December 2018 Security and Quality Rollup.

    Security

    CVE-2018-8540 – Windows Remote Code Execution Vulnerability

    This security update resolves a vulnerability in Microsoft .NET Framework that could allow remote code execution when Microsoft .NET Framework doesn’t validate input correctly. The attacker who successfully exploits this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts that use full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who are granted administrative user rights.

    To exploit the vulnerability, an attacker has to pass specific input to an application that uses susceptible .NET Framework methods.

    This security update addresses the vulnerability by correcting how .NET Framework validates input.

    To learn more about this vulnerability, see Microsoft Common Vulnerabilities and Exposures CVE-2018-8540.

    Getting the Update

    The Security and Quality Rollup is available via Windows Update, Windows Server Update Services, Microsoft Update Catalog, and Docker.


    Read more: .NET Framework December 2018 Security and Quality Rollup | .NET Blog


    Brink's Avatar Posted By: Brink
    12 Dec 2018



 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 10:53.
Find Us