CVE-2022-41064: .NET Framework Information Disclosure Vulnerability

Published Nov 8, 2022
·
Updated

.NET Framework Information Disclosure Vulnerability

Affected Software

143 affected componentsFixes available
Microsoft .NET Framework=4.8
Microsoft .NET Framework=4.8.1
Microsoft Windows Server 2022
Microsoft .NET Framework=4.6.2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft .NET Framework=4.7
Microsoft .NET Framework=4.7.1
Microsoft .NET Framework=4.7.2
Microsoft Windows RT 8.1
Microsoft Windows Server 2008=r2
Microsoft Windows 10=21h1
Microsoft Windows 10=21h1
Microsoft Windows 10=21h1
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
Microsoft Windows 10=21h2
Microsoft Windows 10=21h2
Microsoft Windows 10=21h2
Microsoft Windows 10=20h2
Microsoft Windows 10=20h2
Microsoft Windows 10=20h2
Microsoft Windows 10=22h2
Microsoft Windows 10=22h2
Microsoft Windows 10=22h2
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=1607
Microsoft Windows 10=1607
Microsoft Windows Server 2019
Microsoft Windows Server 2016
Microsoft Windows 8.1
Microsoft Windows 8.1
Microsoft Windows 10
Microsoft Windows 10
Microsoft Windows 11
Microsoft Windows 11=22h2
Microsoft NuGet<1.1.4
Microsoft NuGet>=2.0.0<2.1.2
Microsoft NuGet>=3.0.0<4.8.5
All of the following
Any of the following
Microsoft .NET Framework=4.8
Microsoft .NET Framework=4.8.1
Microsoft Windows Server 2022
All of the following
Microsoft .NET Framework=4.6.2
Any of the following
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
All of the following
Any of the following
Microsoft .NET Framework=4.6.2
Microsoft .NET Framework=4.7
Microsoft .NET Framework=4.7.1
Microsoft .NET Framework=4.7.2
Microsoft .NET Framework=4.8
Any of the following
Microsoft Windows RT 8.1
Microsoft Windows Server 2008=r2
All of the following
Any of the following
Microsoft .NET Framework=4.8
Microsoft .NET Framework=4.8.1
Any of the following
Microsoft Windows 10=21h1
Microsoft Windows 10=21h1
Microsoft Windows 10=21h1
All of the following
Any of the following
Microsoft .NET Framework=4.6.2
Microsoft .NET Framework=4.7
Microsoft .NET Framework=4.7.1
Microsoft .NET Framework=4.7.2
Microsoft .NET Framework=4.8
Any of the following
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
All of the following
Any of the following
Microsoft .NET Framework=4.8
Microsoft .NET Framework=4.8.1
Any of the following
Microsoft Windows 10=21h2
Microsoft Windows 10=21h2
Microsoft Windows 10=21h2
All of the following
Any of the following
Microsoft .NET Framework=4.8
Microsoft .NET Framework=4.8.1
Any of the following
Microsoft Windows 10=20h2
Microsoft Windows 10=20h2
Microsoft Windows 10=20h2
All of the following
Any of the following
Microsoft .NET Framework=4.8
Microsoft .NET Framework=4.8.1
Any of the following
Microsoft Windows 10=22h2
Microsoft Windows 10=22h2
Microsoft Windows 10=22h2
All of the following
Any of the following
Microsoft .NET Framework=4.6.2
Microsoft .NET Framework=4.7
Microsoft .NET Framework=4.7.1
Microsoft .NET Framework=4.7.2
Microsoft .NET Framework=4.8
Any of the following
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
All of the following
Any of the following
Microsoft .NET Framework=4.7.2
Microsoft .NET Framework=4.8
Any of the following
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=1809
All of the following
Microsoft .NET Framework=4.8
Any of the following
Microsoft Windows 10=1607
Microsoft Windows 10=1607
All of the following
Any of the following
Microsoft .NET Framework=4.7.2
Microsoft .NET Framework=4.8
Microsoft Windows Server 2019
All of the following
Microsoft .NET Framework=4.8
Microsoft Windows Server 2016
All of the following
Any of the following
Microsoft .NET Framework=4.7
Microsoft .NET Framework=4.7.1
Microsoft .NET Framework=4.7.2
Microsoft .NET Framework=4.8
Any of the following
Microsoft Windows 8.1
Microsoft Windows 8.1
All of the following
Microsoft .NET Framework=4.6.2
Any of the following
Microsoft Windows 10
Microsoft Windows 10
All of the following
Any of the following
Microsoft .NET Framework=4.8
Microsoft .NET Framework=4.8.1
Any of the following
Microsoft Windows 11
Microsoft Windows 11=22h2
Microsoft .NET Framework=3.5, =4.6.2, =4.7, =4.7.1, =4.7.2
10.0.14393.5501
Microsoft .NET Framework=4.6, =4.6.2
10.0.10240.19567
Microsoft .NET Framework=4.6.2
4.7.04005.026.0.04005.01
Microsoft .NET Framework=4.8
4.8.04584.08
Microsoft .NET Framework=4.8.1
4.8.09110.07
Microsoft .NET Framework=4.8
4.8.04585.026.2.04585.01
Microsoft .NET Framework=4.8
4.8.04584.08
Microsoft .NET Framework=4.8
4.8.04005.02
Microsoft .NET Framework=4.8
4.8.04005.026.3.04585.01
Microsoft .NET Framework=4.8
4.8.04584.08
Microsoft .NET Framework=4.8
10.0.04585.02
Microsoft .NET Framework=4.8
4.8.04585.026.2.04585.01
Microsoft .NET Framework=4.8
4.8.04584.08
Microsoft .NET Framework=4.8
10.0.04585.02
Microsoft .NET Framework=4.8
10.0.09110.12
Microsoft .NET Framework=4.7.2
10.0.04005.02
Microsoft .NET Framework=4.6.2, =4.7, =4.7.1, =4.7.2
4.7.04005.026.0.04005.01
Microsoft .NET Framework=4.8
4.8.04584.08
Microsoft .NET Framework=4.6.2, =4.7, =4.7.1, =4.7.2
4.8.04005.026.3.04005.01
Microsoft .NET Framework=4.8.1
4.8.09110.07
Microsoft .NET Framework=4.8.1
4.8.04584.08
Microsoft .NET Framework=4.8.1
4.8.09110.07
Microsoft .NET Framework=4.6.2, =4.7, =4.7.1, =4.7.2
4.7.04005.026.2.04005.01
Microsoft .NET Framework=4.8.1
4.8.09110.07
Microsoft .NET Framework=4.8.1
4.8.09110.07
Microsoft Nuget 2.1.2<2.1.2
2.1.2
Microsoft Nuget 4.8.5<4.8.4
4.8.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.14393.5501Patch KB5019964
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.10240.19567Patch KB5019970
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.7.04005.02Fixed in 6.0.04005.01Patch KB5020681
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.04584.08Patch KB5020692
  5. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.09110.07Patch KB5020692
  6. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.04585.02Fixed in 6.2.04585.01Patch KB5020678
  7. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.04005.02Patch KB5020690
  8. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.04584.08Patch KB5020801
  9. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.04005.02Fixed in 6.3.04585.01Patch KB5020680
  10. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.04585.02Fixed in 6.2.04585.01Patch KB5020679
  11. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.04584.08Patch KB5020687
  12. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.04585.02Patch KB5020614
  13. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.04584.08Patch KB5020686
  14. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.04585.02Patch KB5020685
  15. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.09110.12Patch KB5020685
  16. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.04005.02Patch KB5020685
  17. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.7.04005.02Fixed in 6.0.04005.01Patch KB5020678
  18. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.04584.08Patch KB5020695
  19. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.04005.02Fixed in 6.3.04005.01Patch KB5020680
  20. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.09110.07Patch KB5020686
  21. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.09110.07Patch KB5020694
  22. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.04584.08Patch KB5020694
  23. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.09110.07Patch KB5020622
  24. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.7.04005.02Fixed in 6.2.04005.01Patch KB5020679
  25. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.09110.07Patch KB5020801
  26. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.09110.07Patch KB5020687
  27. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 4.8.4
  28. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 2.1.2

Event History

Nov 8, 2022
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
Nov 9, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is CVE-2022-41064?

CVE-2022-41064 is a vulnerability in the .NET Framework that allows for information disclosure.

2

What is the severity of CVE-2022-41064?

CVE-2022-41064 has a severity rating of 5.8 (medium).

3

Which software versions are affected by CVE-2022-41064?

Versions 4.8 and 4.8.1 of the .NET Framework are affected by CVE-2022-41064.

4

How can I fix CVE-2022-41064?

To fix CVE-2022-41064, you should update your .NET Framework to a non-vulnerable version.

5

Where can I find more information about CVE-2022-41064?

You can find more information about CVE-2022-41064 on the Microsoft Security Response Center website.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203