Important EPSS 0.06024 2019-07 archive

Executive Summary

An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys. This vulnerability allows an attacker to impersonate another user, which can lead to elevation of privileges. The vulnerability exists in WCF, WIF 3.5 and above in .NET Framework, WIF 1.0 component in Windows, WIF Nuget package, and WIF implementation in SharePoint. An unauthenticated attacker can exploit this by signing a SAML token with any arbitrary symmetric key. This security update addresses the issue by ensuring all versions of WCF and WIF validate the key used to sign SAML tokens correctly.

Overview

Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Elevation of Privilege
Released Jul 9 2019
Last Updated Jul 9 2019
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.06024 — 0.92414 percentile

EPSS Score

0.06024
probability of exploitation in the next 30 days
0.92414 percentile - updated 2026-06-20
View on FIRST.org

Affected Products

138 affected products
Product KB Article Severity Impact Restart Required
Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems 4507419 (Security Update) 4507419 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems 4507419 (Security Update) 4507419 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019 4507419 (Security Update) 4507419 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019 (Server Core installation) 4507419 (Security Update) 4507419 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems 4507419 (Security Update) 4507419 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems 4507419 (Security Update) 4507419 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1903 for 32-bit Systems 4506991 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1903 for x64-based Systems 4506991 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019 4507419 (Security Update) 4507419 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019 (Server Core installation) 4507419 (Security Update) 4507419 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.8 on Windows Server, version 1903 (Server Core installation) 4506991 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 on Windows 10 for 32-bit Systems 4507458 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 for x64-based Systems 4507458 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1607 for 32-bit Systems 4507460 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1607 for x64-based Systems 4507460 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1703 for 32-bit Systems 4507450 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1703 for x64-based Systems 4507450 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1709 for 32-bit Systems 4507455 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1709 for x64-based Systems 4507455 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1803 for 32-bit Systems 4507435 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1803 for x64-based Systems 4507435 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 8.1 for 32-bit systems 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 on Windows 8.1 for x64-based systems 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 on Windows Server 2012 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 on Windows Server 2012 R2 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 on Windows Server 2016 4507460 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows Server 2016 (Server Core installation) 4507460 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows Server, version 1803 (Server Core Installation) 4507435 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5.1 on Windows 7 for 32-bit Systems Service Pack 1 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5.1 on Windows 7 for x64-based Systems Service Pack 1 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5.1 on Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows 7 for 32-bit Systems Service Pack 1 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows 7 for x64-based Systems Service Pack 1 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows 8.1 for 32-bit systems 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows 8.1 for x64-based systems 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows RT 8.1 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows Server 2008 for 32-bit Systems Service Pack 2 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows Server 2008 for x64-based Systems Service Pack 2 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows Server 2012 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows Server 2012 (Server Core installation) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows Server 2012 R2 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows Server 2012 R2 (Server Core installation) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6 on Windows Server 2008 for 32-bit Systems Service Pack 2 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6 on Windows Server 2008 for x64-based Systems Service Pack 2 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2 on Windows 10 for 32-bit Systems 4507458 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 4.6/4.6.1/4.6.2 on Windows 10 for x64-based Systems 4507458 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows 7 for 32-bit Systems Service Pack 1 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows 7 for x64-based Systems Service Pack 1 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows 8.1 for 32-bit systems 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows 8.1 for x64-based systems 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows RT 8.1 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems 4506986 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems 4506986 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1703 for 32-bit Systems 4506987 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1703 for x64-based Systems 4506986 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for 32-bit Systems 4506988 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for x64-based Systems 4506986 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for 32-bit Systems 4506989 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for x64-based Systems 4506989 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 7 for 32-bit Systems Service Pack 1 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 7 for x64-based Systems Service Pack 1 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 8.1 for 32-bit systems 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 8.1 for x64-based systems 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows RT 8.1 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server 2012 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server 2012 R2 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server 2016 4506986 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation) 4506986 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server, version 1803 (Server Core Installation) 4506989 (Security Update) Important Elevation of Privilege Maybe
Microsoft SharePoint Enterprise Server 2013 Service Pack 1 4475522 (Security Update) Important Elevation of Privilege Maybe
Microsoft SharePoint Enterprise Server 2016 4475520 (Security Update) Important Elevation of Privilege Maybe
Microsoft SharePoint Foundation 2010 Service Pack 2 4475510 (Security Update) Important Elevation of Privilege Maybe
Microsoft SharePoint Foundation 2013 Service Pack 1 4475527 (Security Update) Important Elevation of Privilege Maybe
Microsoft SharePoint Server 2019 4475529 (Security Update) Important Elevation of Privilege Maybe
Microsoft.IdentityModel 7.0.0 Release Notes (Security Update) Important Elevation of Privilege Maybe
Windows 10 for 32-bit Systems 4507458 (Security Update) Important Elevation of Privilege Yes
Windows 10 for x64-based Systems 4507458 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for 32-bit Systems 4507460 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for x64-based Systems 4507460 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1703 for 32-bit Systems 4507450 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1703 for x64-based Systems 4507450 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1709 for 32-bit Systems 4507455 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1709 for ARM64-based Systems 4507455 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1709 for x64-based Systems 4507455 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1803 for 32-bit Systems 4507435 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1803 for ARM64-based Systems 4507435 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1803 for x64-based Systems 4507435 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for 32-bit Systems 4507469 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for ARM64-based Systems 4507469 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for x64-based Systems 4507469 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1903 for 32-bit Systems 4507453 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1903 for ARM64-based Systems 4507453 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1903 for x64-based Systems 4507453 (Security Update) Important Elevation of Privilege Yes
Windows 7 for 32-bit Systems Service Pack 1 4507449 (Monthly Rollup) 4507456 (Security Only) Important Elevation of Privilege Yes
Windows 7 for x64-based Systems Service Pack 1 4507449 (Monthly Rollup) 4507456 (Security Only) Important Elevation of Privilege Yes
Windows 8.1 for 32-bit systems 4507448 (Monthly Rollup) 4507457 (Security Only) 4507448 (Monthly Rollup) Important Elevation of Privilege Yes
Windows 8.1 for x64-based systems 4507448 (Monthly Rollup) 4507457 (Security Only) 4507448 (Monthly Rollup) Important Elevation of Privilege Yes
Windows RT 8.1 4507448 (Monthly Rollup) 4507448 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2008 for 32-bit Systems Service Pack 2 4507452 (Monthly Rollup) 4507461 (Security Only) Important Elevation of Privilege Yes
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 4507452 (Monthly Rollup) 4507461 (Security Only) Important Elevation of Privilege Yes
Windows Server 2008 for Itanium-Based Systems Service Pack 2 4507452 (Monthly Rollup) 4507461 (Security Only) Important Elevation of Privilege Yes
Windows Server 2008 for x64-based Systems Service Pack 2 4507452 (Monthly Rollup) 4507461 (Security Only) Important Elevation of Privilege Yes
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 4507452 (Monthly Rollup) 4507461 (Security Only) Important Elevation of Privilege Yes
Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1 4507449 (Monthly Rollup) 4507456 (Security Only) Important Elevation of Privilege Yes
Windows Server 2008 R2 for x64-based Systems Service Pack 1 4507449 (Monthly Rollup) 4507456 (Security Only) Important Elevation of Privilege Yes
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 4507449 (Monthly Rollup) 4507456 (Security Only) Important Elevation of Privilege Yes
Windows Server 2012 4507462 (Monthly Rollup) 4507464 (Security Only) Important Elevation of Privilege Yes
Windows Server 2012 (Server Core installation) 4507462 (Monthly Rollup) 4507464 (Security Only) Important Elevation of Privilege Yes
Windows Server 2012 R2 4507448 (Monthly Rollup) 4507457 (Security Only) 4507448 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 R2 (Server Core installation) 4507448 (Monthly Rollup) 4507457 (Security Only) 4507448 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2016 4507460 (Security Update) Important Elevation of Privilege Yes
Windows Server 2016 (Server Core installation) 4507460 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 4507469 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 (Server Core installation) 4507469 (Security Update) Important Elevation of Privilege Yes
Windows Server, version 1803 (Server Core Installation) 4507435 (Security Update) Important Elevation of Privilege Yes
Windows Server, version 1903 (Server Core installation) 4507453 (Security Update) Important Elevation of Privilege Yes

Patches

29 patches
Article Type Restart
4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 (Security Only) 4507423 (Monthly Rollup) 4507414 Monthly Rollup Maybe
4507419 (Security Update) 4507419 Security Update Maybe
4506991 Security Update Maybe
4507458 Security Update Yes
4507460 Security Update Yes
4507450 Security Update Yes
4507455 Security Update Yes
4507435 Security Update Yes
4507422 (Monthly Rollup) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507413 (Security Only) 4507413 (Security Only) 4507422 (Monthly Rollup) 4507413 Monthly Rollup Maybe
4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 (Security Only) 4507421 (Monthly Rollup) 4507412 Monthly Rollup Maybe
4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 (Security Only) 4507420 (Monthly Rollup) 4507411 Monthly Rollup Maybe
4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 (Monthly Rollup) 4507422 Monthly Rollup Maybe
4506986 Security Update Maybe
4506987 Security Update Maybe
4506988 Security Update Maybe
4506989 Security Update Maybe
4475522 Security Update Maybe
4475520 Security Update Maybe
4475510 Security Update Maybe
4475527 Security Update Maybe
4475529 Security Update Maybe
Release Notes Security Update Maybe
4507469 Security Update Yes
4507453 Security Update Yes
4507449 (Monthly Rollup) 4507456 Monthly Rollup Yes
4507448 (Monthly Rollup) 4507457 (Security Only) 4507448 Monthly Rollup Yes
4507448 (Monthly Rollup) 4507448 Monthly Rollup Yes
4507452 (Monthly Rollup) 4507461 Monthly Rollup Yes
4507462 (Monthly Rollup) 4507464 Monthly Rollup Yes

Known Exploits

Acknowledgments

Oleksandr Mirosh (@olekmirosh) and Alvaro Munoz (@pwntester) from Micro Focus Fortify