News

Microsoft's May Security Update Includes .NET Framework Vulnerabilities

Buried in Microsoft's May bulletins are two .NET Framework fixes that are rated critical and important.

File this under "In Case You Missed It": Microsoft earlier this month, during it's usual security patch update cycle, released two bulletins that had to do with two .NET Framework flaws.

The first, MS15-044, was for a flaw rated critical that could allow remote code execution if a user opens a compromised document or Web page. The flaws specifically pertain to how certain Microsoft technologies parse OpenType and TrueType fonts. In both cases, the bulletin notes that a fix has been made to the way the Windows DirectWrite Library in the Windows OS handles OpenType and TrueType fonts. A full list of the affected software is listed in the bulletin.

In MS15-048, a security update was issued for a flaw that allow a hacker to gain an elevation of privilege through a user's compromised system if that user is tricked into installing a "specially crafted partial trust application." The elevation of privilege could then allow a denial of service attack to disrupt a .NET-enabled site and any apps using .NET Framework. The update corrects "how the .NET Framework decrypts XML data."

On a related note, 1105's senior news producer Kurt Mackie reports on the incremental changes that will be coming to the security update cycle, as the company gets closer to releasing Windows 10. "Windows 10, when it gets released as a final product, will have a faster update cycle that will include the delivery of new features along with security patches," writes Mackie. You can read more about it on MCPmag.com here.

About the Author

You Tell 'Em, Readers: If you've read this far, know that Michael Domingo, Visual Studio Magazine Editor in Chief, is here to serve you, dear readers, and wants to get you the information you so richly deserve. What news, content, topics, issues do you want to see covered in Visual Studio Magazine? He's listening at [email protected].

comments powered by Disqus

Featured

  • Mastering Blazor Authentication and Authorization

    At the Visual Studio Live! @ Microsoft HQ developer conference set for August, Rockford Lhotka will explain the ins and outs of authentication across Blazor Server, WebAssembly, and .NET MAUI Hybrid apps, and show how to use identity and claims to customize application behavior through fine-grained authorization.

  • Linear Support Vector Regression from Scratch Using C# with Evolutionary Training

    Dr. James McCaffrey from Microsoft Research presents a complete end-to-end demonstration of the linear support vector regression (linear SVR) technique, where the goal is to predict a single numeric value. A linear SVR model uses an unusual error/loss function and cannot be trained using standard simple techniques, and so evolutionary optimization training is used.

  • Low-Code Report Says AI Will Enhance, Not Replace DIY Dev Tools

    Along with replacing software developers and possibly killing humanity, advanced AI is seen by many as a death knell for the do-it-yourself, low-code/no-code tooling industry, but a new report belies that notion.

  • Vibe Coding with Latest Visual Studio Preview

    Microsoft's latest Visual Studio preview facilitates "vibe coding," where developers mainly use GitHub Copilot AI to do all the programming in accordance with spoken or typed instructions.

  • Steve Sanderson Previews AI App Dev: Small Models, Agents and a Blazor Voice Assistant

    Blazor creator Steve Sanderson presented a keynote at the recent NDC London 2025 conference where he previewed the future of .NET application development with smaller AI models and autonomous agents, along with showcasing a new Blazor voice assistant project demonstrating cutting-edge functionality.

Subscribe on YouTube