Important EPSS 0.0097 2019-09 archive

Executive Summary

An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations. An attacker who successfully exploited this vulnerability could write files to folders that require higher privileges than what the attacker already has. To exploit the vulnerability, an attacker would need to log into a system. The attacker could then specify the targeted folder and trigger an affected process to run. The update addresses the vulnerability correcting how the .NET Framework CLR process logs data.

Overview

Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Elevation of Privilege
Released Sep 10 2019
Last Updated Sep 10 2019
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.0097 — 0.57261 percentile

EPSS Score

0.0097
probability of exploitation in the next 30 days
0.57261 percentile - updated 2026-06-20
View on FIRST.org

Affected Products

62 affected products
Product KB Article Severity Impact Restart Required
Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems 4514601 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems 4514601 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019 4514601 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019 (Server Core installation) 4514601 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems 4514601 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems 4514601 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1903 for 32-bit Systems 4514359 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1903 for x64-based Systems 4514359 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019 4514601 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019 (Server Core installation) 4514601 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 AND 4.8 on Windows Server, version 1903 (Server Core installation) 4514359 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 on Windows 10 for 32-bit Systems 4516070 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 for x64-based Systems 4516070 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1607 for 32-bit Systems 4516044 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1607 for x64-based Systems 4516044 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1703 for 32-bit Systems 4516068 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1703 for x64-based Systems 4516068 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1709 for 32-bit Systems 4516066 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1709 for x64-based Systems 4516066 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1803 for 32-bit Systems 4516058 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 10 Version 1803 for x64-based Systems 4516058 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows 8.1 for 32-bit systems 4514604 (Monthly Rollup) 4514599 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 on Windows 8.1 for x64-based systems 4514599 (Security Only) 4514604 (Monthly Rollup) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 on Windows Server 2012 4514603 (Monthly Rollup) 4514598 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation) 4514603 (Monthly Rollup) 4514598 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 on Windows Server 2012 R2 4514599 (Security Only) 4514604 (Monthly Rollup) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation) 4514599 (Security Only) 4514604 (Monthly Rollup) Important Elevation of Privilege Maybe
Microsoft .NET Framework 3.5 on Windows Server 2016 4516044 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows Server 2016 (Server Core installation) 4516044 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 3.5 on Windows Server, version 1803 (Server Core Installation) 4516058 (Security Update) Important Elevation of Privilege Yes
Microsoft .NET Framework 4.5.2 on Windows 8.1 for 32-bit systems 4514604 (Monthly Rollup) 4514599 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows 8.1 for x64-based systems 4514604 (Monthly Rollup) 4514599 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows RT 8.1 4514604 (Monthly Rollup) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows Server 2012 4514603 (Monthly Rollup) 4514598 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows Server 2012 (Server Core installation) 4514603 (Monthly Rollup) 4514598 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows Server 2012 R2 4514604 (Monthly Rollup) 4514599 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.5.2 on Windows Server 2012 R2 (Server Core installation) 4514604 (Monthly Rollup) 4514599 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows 8.1 for 32-bit systems 4514604 (Monthly Rollup) 4514599 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows 8.1 for x64-based systems 4514604 (Monthly Rollup) 4514599 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows RT 8.1 4514604 (Monthly Rollup) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 4514603 (Monthly Rollup) 4514598 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation) 4514603 (Monthly Rollup) 4514598 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 4514604 (Monthly Rollup) 4514599 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation) 4514604 (Monthly Rollup) 4514599 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems 4514354 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems 4514354 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1703 for 32-bit Systems 4514355 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1703 for x64-based Systems 4514355 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for 32-bit Systems 4514356 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for x64-based Systems 4514356 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for 32-bit Systems 4514357 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for x64-based Systems 4514357 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 8.1 for 32-bit systems 4514604 (Monthly Rollup) 4514599 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows 8.1 for x64-based systems 4514604 (Monthly Rollup) 4514599 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows RT 8.1 4514604 (Monthly Rollup) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server 2012 4514603 (Monthly Rollup) 4514598 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation) 4514603 (Monthly Rollup) 4514598 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server 2012 R2 4514604 (Monthly Rollup) 4514599 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation) 4514604 (Monthly Rollup) 4514599 (Security Only) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server 2016 4514354 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation) 4514354 (Security Update) Important Elevation of Privilege Maybe
Microsoft .NET Framework 4.8 on Windows Server, version 1803 (Server Core Installation) 4516058 (Security Update) Important Elevation of Privilege Yes

Patches

15 patches
Article Type Restart
4514601 Security Update Maybe
4514359 Security Update Maybe
4516070 Security Update Yes
4516044 Security Update Yes
4516068 Security Update Yes
4516066 Security Update Yes
4516058 Security Update Yes
4514604 (Monthly Rollup) 4514599 Monthly Rollup Maybe
4514599 (Security Only) 4514604 Security Only Maybe
4514603 (Monthly Rollup) 4514598 Monthly Rollup Maybe
4514604 Monthly Rollup Maybe
4514354 Security Update Maybe
4514355 Security Update Maybe
4514356 Security Update Maybe
4514357 Security Update Maybe

Known Exploits

Acknowledgments