GitHub Copilot is now available for free

No trial. No credit card required. Just your GitHub account.

November 14th, 2023
0 reactions

.NET Framework November 2023 Security and Quality Rollup

Revised12/19/23:To add missing product versions of Windows Server 2012 and Windows Server 2012 R2.

Revised11/15/23:To remove CVE details which were not affected by the .NET Framework November Security and Quality rollup.

Today, we are releasing the November 2023 Security and Quality Rollup updates for .NET Framework.

Security

CVE-2023-36560 – .NET Framework Security Feature Bypass Vulnerability

This security update addresses a security feature bypass vulnerability detailed inCVE 2023-36560.

CVE-2023-36049 – .NET Framework Elevation of Privilege Vulnerability

This security update addresses a elevation of privilege vulnerability detailed inCVE 2023-36049.

Quality and Reliability

This release contains the following quality and reliability improvements.

WPF1
  • Addresses an issue to provide an appconfig mechanism to allow users to extend the list of allowed types in case of XAML/XPS parsing. (applies to: .NET Framework 4.8.1)

1Windows Presentation Foundation (WPF)

Getting the Update

The Security and Quality Rollup is available via Windows Update, Windows Server Update Services, and Microsoft Update Catalog. The Security Only Update is available via Windows Server Update Services and Microsoft Update Catalog.

Microsoft Update Catalog

You can get the update via the Microsoft Update Catalog. For Windows 10, NET Framework 4.8 updates are available via Windows Update, Windows Server Update Services, Microsoft Update Catalog. Updates for other versions of .NET Framework are part of the Windows 10 Monthly Cumulative Update.

**Note**: Customers that rely on Windows Update and Windows Server Update Services will automatically receive the .NET Framework version-specific updates. Advanced system administrators can also take use of the below direct Microsoft Update Catalog download links to .NET Framework-specific updates. Before applying these updates, please ensure that you carefully review the .NET Framework version applicability, to ensure that you only install updates on systems where they apply.

The following table is for Windows 10+ and Windows Server 2016+ versions.

Product VersionCumulative Update
Microsoft server operating system, version 23H2
.NET Framework 3.5, 4.8.1Catalog5032004
Windows 11, version 22H2 and Windows 11, version 23H2
.NET Framework 3.5, 4.8.1Catalog5032007
Windows 11, version 21H25032340
.NET Framework 3.5, 4.8Catalog5031991
.NET Framework 3.5, 4.8.1Catalog5032006
Microsoft server operating system, version 22H25032478
.NET Framework 3.5, 4.8Catalog5031993
.NET Framework 3.5, 4.8.1Catalog5032008
Microsoft server operating system version 21H25032336
.NET Framework 3.5, 4.8Catalog5031993
.NET Framework 3.5, 4.8.1Catalog5032008
Windows 10, version 22H25032339
.NET Framework 3.5, 4.8Catalog5031988
.NET Framework 3.5, 4.8.1Catalog5032005
Windows 10, version 21H25032338
.NET Framework 3.5, 4.8Catalog5031988
.NET Framework 3.5, 4.8.1Catalog5032005
Windows 10, version 1809 and Windows Server 20195032337
.NET Framework 3.5, 4.7.2Catalog5031984
.NET Framework 3.5, 4.8Catalog5031990
.NET Framework 3.5, 4.8Catalog5018210
Windows 10, version 1607 and Windows Server 2016
.NET Framework 3.5, 3.5 + 4.6.2, 4.7, 4.7.1, 4.7.2Catalog5032197
.NET Framework 4.8Catalog5031989
Windows 10, version 1507
.NET Framework 3.5, 3.5 + 4.6, 4.6.2Catalog5032199

The following table is for earlier Windows and Windows Server versions.

Product VersionSecurity and Quality RollupSecurity Only Update
Windows Server 2012 R25032343
.NET Framework 3.5Catalog5032001
.NET Framework 4.6.2, 4.7, 4.7.1, 4.7.2Catalog5031986
.NET Framework 4.8Catalog5031994
Windows Server 20125032342
.NET Framework 3.5Catalog5031998
.NET Framework 4.6.2, 4.7, 4.7.1, 4.7.2Catalog5031985
.NET Framework 4.8Catalog5031992
Windows Server 2008 R250323415032185
.NET Framework 3.5.1Catalog5032000Catalog5032012
.NET Framework 4.6.2, 4.7, 4.7.1, 4.7.2Catalog5031987Catalog5032009
.NET Framework 4.8Catalog5031995Catalog5032010
Windows Server 200850323445032186
.NET Framework 2.0, 3.0Catalog5031999Catalog5032011
.NET Framework 4.6.2Catalog5031987Catalog5032009

The operating system row lists a KB which will be used for update offering purposes. When the operating system KB is offered, the applicability logic will determine the specific .NET Framework update(s) will be installed. Updates for individual .NET Framework versions will be installed based on the version of .NET Framework that is already present on the device. Because of this the operating system KB is not expected to be listed as installed updates on the device. The expected update to be installed are the .NET Framework specific version updates listed in the table above.

 

Previous Monthly Rollups

The last few .NET Framework Monthly updates are listed below for your convenience:

Author

Immo Landwerth
Program Manager

Immo Landwerth is a program manager on the .NET Framework team at Microsoft. He specializes in API design, the base class libraries (BCL), and .NET Standard. He works on base class libraries which represents the core types of the .NET platform, such as string and int but also includes collections and IO.He's involved with portable class libraries and works on shipping more framework components in an out-of-band fashion via NuGet.

Tara Overfield
Senior Software Engineer

Tara is a Software Engineer on the .NET team. She works on releasing .NET Framework updates.

8 comments

Discussion is closed.Login to edit/delete existing comments.

Stay informed

Get notified when new posts are published.
Follow this blog
facebooklinkedinyoutubetwitchStackoverflow