.NET Framework September 2017 Security and Quality Rollup

Brink

Administrator
Staff member
Local time
7:49 PM
Messages
74,846
Location
Oklahoma
Today, we are releasing the September 2017 Security and Quality Rollup and Security Only Update.This update applies to Windows 7 and later client versions and Windows Server 2008 and later server versions.

Security

This release contains the following security changes.

CVE-2017-8759 | .NET Framework Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input. An attacker who successfully exploited this vulnerability in software using the .NET framework could take control of an affected system. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

To exploit the vulnerability, an attacker would first need to convince the user to open a malicious document or application.

The security update addresses the vulnerability by correcting how .NET validates untrusted input.

More Information: CVE-2017-8759

Quality and Reliability

This release contains the following quality and reliability improvements.

ASP.NET

  • Values added to System.Web.Cache expire immediately, with .NET Framework 4.7. [452228]
  • ASP.NET site running on Sitefinity broken, with .NET Framework 4.7. [457739]
CLR

  • CRWLock::StaticAcquireWriterLock() never returns if Int32.MaxValue number of ReaderWriterLock objects are created, with .NET Framework 3.5. [242568]
  • Crash in CLR assembly metadata reader. [367294]
  • .NET remoting IPC listener thread exits and leaves an orphaned IPCServerchannel. [454409]
  • Silent bad codegen when optimizing expression. [460765]
  • Crash in Visual Studio due to race in CLR assembly loader. [462762]
  • Runtime underallocates arrays by one element in rare cases when jitting large methods. [463604]
  • AppContext feature opt-in/out not functioning correctly. [469020]
Management

  • Reboot method of Win32_OperatingSystem has Privilege not held exception [441901]
Networking

  • HTTPWebRequest times out when switching to TLS after installing update KB4019112. [465796]
WCF

  • NetTcp with X509Certificates using SslStream uses the default TLS version as the OS, with .NET Framework 4.7. [451528]
Windows Forms

  • Excessive object creation in a performance-critical code-path leading to performance regressions and/or displaying empty UI and/or exhausting GDI+ handles. [452048]
  • Multi-Mon support: Controls with non-default anchoring are moved around the screen when scaling is changed [462872].
    • Note: This fix will be made available for Windows 10 1607 (Anniversary Update) in October.
WPF

  • WPF fails to load resources if two versions of the same assembly are loaded. [378607]
    • Note: This fix will be made available for Windows 10 1703 (Creators Update) in October.
  • WPF consumes high % of CPU in Visual Studio when console session not active. [391184]
    • Note: This fix will be made available for Windows 10 in October.
  • Visual Studio fails due to “Unable to load DLL ‘PenIMC.dll’” error. [452476]
    • Note: This fix will be made available for Windows 10 1703 (Creators Update) in October.
  • Application crash due to call into DWrite. [453529]
    • Note: This fix will be made available for Windows 10 in October.
  • TargetFrameworkName is null with mixed mode application. [425074]
    • Note: This fix will be made available for Windows 10 1703 (Creators Update) in October.
  • Event leak with WPF application on touch screen monitors on Windows 10. [434946]
    • Note: This fix will be made available for Windows 10 1703 (Creators Update) in October.
Note: Fixes are not always available for all Windows versions at the same time. This situation is noted where appropriate, and where the information is available, a release date is provided.

Note: Additional information on these improvements is not available. The VSTS bug number provided with each improvement is a unique ID that you can give Microsoft Customer Support, include in StackOverflow commentsor use in web searches.

Getting the Update

The Security and Quality Rollup is available via Windows Update, Windows Server Update Services, Microsoft Update Catalog, and Docker.

Microsoft Update Catalog

You can get the update via the Microsoft Update Catalog. For Windows 10, .NET Framework updates are part of the Windows 10 Monthly Rollup.


Docker Images

Docker images has not yet been updated as part of today’s release. They will be updated in the shortly. This post will be updated at that time.


Read more: .NET Framework September 2017 Security and Quality Rollup | .NET Blog
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
my friend brink where is the real rollup.net download link? it appears many confused links. i dont know which.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate x64
CPU
intel core i7 2600
Motherboard
abit
Memory
32gb
Graphics Card(s)
3 sli x16
Hard Drives
12 hdd
Antivirus
norton
Browser
internet explorer
Hello Jonathan, :)

If you have Microsoft .NET Framework installed, the update should be available via Windows Update.

For via Microsoft Update Catalog: Microsoft Update Catalog
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
Hello Jonathan, :)

If you have Microsoft .NET Framework installed, the update should be available via Windows Update.

For via Microsoft Update Catalog: Microsoft Update Catalog

Thank you brink, u're really apreciated due your contributions:o.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate x64
CPU
intel core i7 2600
Motherboard
abit
Memory
32gb
Graphics Card(s)
3 sli x16
Hard Drives
12 hdd
Antivirus
norton
Browser
internet explorer
Thanks, Brink. You're always on the ball.

1--MS sends me updates almost daily. PITA. Used to be only on Tues.

2--I have Office 2003 installed, although I don't use it. It's for a hypothetical emergency where Open Office can't open a file. MS Updater keeps showing me Office 10 updates and I keep telling it to "Hide these updates," and they keep coming back, sometimes all, sometimes a few. Any ideas?
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP p6-2020t
OS
Win 7 Ult 64-bit
CPU
G620 2.6GHZ Pentium R
Memory
6 GB
Monitor(s) Displays
25" HPLV2311
Screen Resolution
1920 x 1200
Hard Drives
1 SATA, 1 exterior SATA
Case
HP
Cooling
PSU
Antivirus
Glasswire
Browser
Waterfox; Firefox; Chrome for work
Other Info
Firewall--Glasswire
Similar specs in Gateway DX4200
Verizon FIOS Wired network

1 other Win7 computer-- has SSD
Back
Top