November 14, 2023 - KB5032007 Cumulative Update for .NET Framework 3.5 and 4.8.1 for Windows 11, version 22H2 and Windows 11, version 23H2
The November 14, 2023 update for Windows 11, version 22H2 and Windows 11, version 23H2 includes security and cumulative reliability improvements in .NET Framework 3.5 and 4.8.1. We recommend that you apply this update as part of your regular maintenance routines. Before you install this update, see the Prerequisites and Restart requirement sections.
Summary
Security Improvements
CVE-2023-36560 – .NET Framework Security Feature Bypass Vulnerability
This security update addresses a security feature bypass vulnerability detailed in CVE-2023-36560.
CVE-2023-36558 – .NET Framework Security Feature Bypass Vulnerability
This security update addresses a security feature bypass vulnerability detailed in CVE-2023-36558.
CVE-2023-36049 – .NET Framework Elevation of Privilege Vulnerability
This security update addresses a elevation of privilege vulnerability detailed in CVE-2023-36049.
CVE-2023-36038 – .NET Framework Denial of Service Vulnerability
This security update addresses a denial of service vulnerability detailed in CVE-2023-36038.
Quality and Reliability Improvements
1Windows Presentation Foundation (WPF)
WPF1 - Addresses an issue to provide an appconfig mechanism to allow users to extend the list of allowed types in case of XAML/XPS parsing.
Known issues in this update
Microsoft is not currently aware of any issues in this update.
How to get this update
Install this update
Release Channel Available Next Step Windows Update and Microsoft Update Yes None. This update will be downloaded and installed automatically from Windows Update. Windows Update for Business Yes None. This update will be downloaded and installed automatically from Windows Update. Microsoft Update Catalog Yes To get the standalone package for this update, go to the Microsoft Update Catalog website. Windows Server Update Services (WSUS) Yes This update will automatically sync with WSUS if you configure as follows:
Product: Windows 11, version 22H2 and Windows 11, version 23H2
Classification: Security Updates
File information
For a list of the files that are provided in this update, download the file information for cumulative update.
Prerequisites
To apply this update, you must have .NET Framework 3.5 or 4.8.1 installed.
Restart requirement
You must restart the computer after you apply this update if any affected files are being used. We recommend that you exit all .NET Framework-based applications before you apply this update.
Source:
.NET Framework November 2023 Security and Quality Rollup - .NET Blog
November 2023 Security and Quality Rollup Updates for .NET Framework
devblogs.microsoft.com
Last edited: