Microsoft just announced that it has re-issued the buggy July .NET Security Only patches identified as CVE–2020-1147, and covering a gazillion differ
[See the full post at: Microsoft re-releases buggy July .NET Security Only patches]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Microsoft re-releases buggy July .NET Security Only patches
Home » Forums » Newsletter and Homepage topics » Microsoft re-releases buggy July .NET Security Only patches
- This topic has 15 replies, 11 voices, and was last updated 4 years, 7 months ago.
AuthorTopicViewing 6 reply threadsAuthorReplies-
GoneToPlaid
AskWoody Lounger -
Paul T
AskWoody MVP
-
-
Alex5723
AskWoody PlusOctober 14, 2020 at 4:32 am #2304147From Microsoft.
Summary
=======The following CVEs have undergone a major revision increment:
* CVE-2019-1181
* CVE-2019-1182
* CVE-2020-1147Revision Information:
=====================* CVE-2019-1181
– CVE-2019-1181 | Remote Desktop Services Remote Code Execution Vulnerability
– https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-1181– Version 2.0
– Reason for Revision: Revised the Security Updates table to add Microsoft Remote
Desktop for Android, Microsoft Remote Desktop for Mac, and Microsoft Remote Desktop
for Mac IoS because these apps are affected by this vulnerability. Microsoft
recommends that customers running any of these apps install the latest security
update to be fully protected from this vulnerability. Please see the FAQ section
for information on how to get these updates.
– Originally posted: August 13, 2020
– Updated: October 13, 2020
– Aggregate CVE Severity Rating: Critical* CVE-2019-1182
– CVE-2019-1182 | Remote Desktop Services Remote Code Execution Vulnerability
– https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-1182– Version 2.0
– Reason for Revision: Revised the Security Updates table to add Microsoft Remote
Desktop for Android, Microsoft Remote Desktop for Mac, and Microsoft Remote Desktop
for Mac IoS because these apps are affected by this vulnerability. Microsoft
recommends that customers running any of these apps install the latest security
update to be fully protected from this vulnerability. Please see the FAQ section
for information on how to get these updates.
– Originally posted: August 13, 2020
– Updated: October 13, 2020
– Aggregate CVE Severity Rating: Critical* CVE-2020-1147
– CVE-2020-1147 | .NET Framework, SharePoint Server, and Visual Studio Remote Code
Execution Vulnerability
– https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1147– Version 2.0
– Reason for Revision: To comprehensively address CVE-2020-1147, Microsoft has released
the following: October Security Updates for all affected versions of .NET Framework
installed on Windows 10; October 2020 Monthly Rollup updates AND updated versions of
the Security Only updates released in July 2020 for all affected versions of .NET
Framework installed on Windows 8.1, Windows Server 2012 R2, Windows Server 2012,
Windows 7, Windows Server 2008 R2, and Windows Server 2008. Microsoft strongly
recommends that customers install the updates to be fully protected from the
vulnerability. Customers who install the Security Only updates should ensure that
they re-install the updates after October 13. Customers whose systems are configured
to receive automatic updates do not need to take any further action.
– Originally posted: July 14, 2020
– Updated: October 13, 2020
– Aggregate CVE Severity Rating: Critical**************************************************************************************
1 user thanked author for this post.
-
anonymous
Guest -
PKCano
ManagerOctober 14, 2020 at 9:39 am #2304198This is NOT the .Net Security & Quality Rollup issued through Windows Update.
It is a Security-only Rollup that is downloadable from the Microsoft Catalog only.The recommendation is NOT to install the buggy July patch.
The recommendation is to install the FIXED patch re-released on Oct. 13 Patch Tuesday to correct the bugs in the July update.
-
-
CraigS26
AskWoody PlusOctober 14, 2020 at 11:20 am #2304229Is this the KB (4578974) .NET patch?
Ref Buggy July Patch fix ….Yes for my 1909. Search showed 7/14/20 Orig Publish and latest Oct 13 ’20.
W10 Pro 22H2 / Hm-Stdnt Ofce '16 C2R / Macrium Pd vX / GP=2 + FtrU=Semi-Annual + Feature Defer = 1 + QU = 0
-
This reply was modified 4 years, 7 months ago by
CraigS26.
-
This reply was modified 4 years, 7 months ago by
-
DKThompson
AskWoody PlusOctober 14, 2020 at 2:22 pm #2304292Install .NET patches or NOT install????
In Ms Bradley’s 12 Oct 2020 article “How to block the Windows 10 October 2020 Update, version 20H2, from installing”
Under step 3, she said “If you’re on version 1909 or 2004, don’t click that link. If you want to avoid installing Windows 10 version 20H2, don’t click the Download and install link. And always remember — you don’t want to click Check for updates, as this will offer up optional .NET updates on your system that you don’t want installed.”
On Oct 13, 2020 Woody posted this note: “Microsoft re-releases buggy July .NET Security Only patches” where he said “Anyway, if you see a .NET patch from July suddenly appear in October, you need to install it, and now you know why.”
Please advise what the .NET patch means to the average user and when should they be installed
—————————————
Win Pro 2004 OS Build 19041.508 -
PKCano
ManagerOctober 14, 2020 at 2:36 pm #2304293The .NET patches in question were Security-only for Win7 and Win8.1 that were downloadable only from the MS Catalog. If you have not been downloading SOs and manually installing them, you have nothing to worry about.
However, if this was your case, for Win7 see #2304011
If you need the info about Win8.1 .NET SO patches re-released from July, let me know ans I will give you the necessary links.The .NET patches for Win10 are Previews, not the Patch Tuesday Security .NET CUs. We don’t recommend installing Previews, so that is what Susan was referring to.
1 user thanked author for this post.
-
anonymous
GuestOctober 14, 2020 at 3:24 pm #2304301In the title, or immediately below the title in a subtitle/other entry one must always include the OSs affected 7, and/or 8/8.1 and/or 10/versions. But “Security Only” does give a hint that it’s 7/8/8.1 sort of issue, if I’m correct.
I’m Windows 10 Home(1909), take it all eventually, Edition after all the Pause Updates clicks expire.
1 user thanked author for this post.
-
PKCano
ManagerOctober 14, 2020 at 3:29 pm #2304313You are right about including the version numbers.
BUT, Win10 does not have Security-only patches of any kind. So you would not be seeing anything like that.
Win7/8.1 Security-only patches are never released through Windows Update. They are MS Catalog download only and manual install. So even Win7/8.1 users would not receive them unknowingly.
1 user thanked author for this post.
-
-
-
-
J9438
AskWoody PlusOctober 15, 2020 at 8:06 am #2304470 -
PKCano
ManagerOctober 15, 2020 at 8:11 am #2304471The re-released .NET Security-only patches are for WIn7 and Win8.1 only. They are not even issued through Windows Update for these two versions. They are manual download/install only.
They are NOT for Win10. Win10 does not have Security-only anything.
1 user thanked author for this post.
-
-
PerthMike
AskWoody PlusOctober 19, 2020 at 9:51 pm #2305589The re-released .NET Security-only patches are for WIn7 and Win8.1 only. They are not even issued through Windows Update for these two versions. They are manual download/install only.
They are NOT for Win10. Win10 does not have Security-only anything.
Also for Windows 8/2012 Server.
No matter where you go, there you are.
Viewing 6 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Discover the Best AI Tools for Everything
by
Alex5723
6 hours, 39 minutes ago -
Edge Seems To Be Gaining Weight
by
bbearren
1 hour, 25 minutes ago -
Rufus is available from the MSFT Store
by
PL1
17 hours, 37 minutes ago -
Microsoft : Ending USB-C® Port Confusion
by
Alex5723
19 hours, 46 minutes ago -
KB5061768 update for Intel vPro processor
by
drmark
2 hours, 11 minutes ago -
Outlook 365 classic has exhausted all shared resources
by
drmark
17 hours, 57 minutes ago -
My Simple Word 2010 Macro Is Not Working
by
mbennett555
15 hours, 32 minutes ago -
Office gets current release
by
Susan Bradley
18 hours, 9 minutes ago -
FBI: Still Using One of These Old Routers? It’s Vulnerable to Hackers
by
Alex5723
2 days, 8 hours ago -
Windows AI Local Only no NPU required!
by
RetiredGeek
1 day, 16 hours ago -
Stop the OneDrive defaults
by
CWBillow
2 days, 9 hours ago -
Windows 11 Insider Preview build 27868 released to Canary
by
joep517
2 days, 18 hours ago -
X Suspends Encrypted DMs
by
Alex5723
2 days, 21 hours ago -
WSJ : My Robot and Me AI generated movie
by
Alex5723
2 days, 21 hours ago -
Botnet hacks 9,000+ ASUS routers to add persistent SSH backdoor
by
Alex5723
2 days, 22 hours ago -
OpenAI model sabotages shutdown code
by
Cybertooth
2 days, 22 hours ago -
Backup and access old e-mails after company e-mail address is terminated
by
M W Leijendekker
2 days, 10 hours ago -
Enabling Secureboot
by
ITguy
2 days, 17 hours ago -
Windows hosting exposes additional bugs
by
Susan Bradley
3 days, 6 hours ago -
No more rounded corners??
by
CWBillow
3 days, 2 hours ago -
Android 15 and IPV6
by
Win7and10
2 days, 16 hours ago -
KB5058405 might fail to install with recovery error 0xc0000098 in ACPI.sys
by
Susan Bradley
3 days, 18 hours ago -
T-Mobile’s T-Life App has a “Screen Recording Tool” Turned on
by
Alex5723
3 days, 21 hours ago -
Windows 11 Insider Preview Build 26100.4202 (24H2) released to Release Preview
by
joep517
3 days, 16 hours ago -
Windows Update orchestration platform to update all software
by
Alex5723
4 days, 4 hours ago -
May preview updates
by
Susan Bradley
3 days, 16 hours ago -
Microsoft releases KB5061977 Windows 11 24H2, Server 2025 emergency out of band
by
Alex5723
3 days, 7 hours ago -
Just got this pop-up page while browsing
by
Alex5723
3 days, 21 hours ago -
KB5058379 / KB 5061768 Failures
by
crown
3 days, 18 hours ago -
Windows 10 23H2 Good to Update to ?
by
jkitc
2 days, 20 hours ago
Recent blog posts
Key Links
S | M | T | W | T | F | S |
---|---|---|---|---|---|---|
1 | 2 | 3 | 4 | 5 | 6 | 7 |
8 | 9 | 10 | 11 | 12 | 13 | 14 |
15 | 16 | 17 | 18 | 19 | 20 | 21 |
22 | 23 | 24 | 25 | 26 | 27 | 28 |
29 | 30 |
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.