NAVANEM
.NET FrameworkOS build Windows 11 25H2 / Server 24H2

KB5087051: .NET Framework 3.5 and 4.8.1 Cumulative Update for Windows 11 25H2 and Server 24H2

May 12, 2026 security update for .NET Framework 3.5 and 4.8.1 on Windows 11 25H2 and Server 24H2, addressing two Elevation of Privilege vulnerabilities.

KB5087051: .NET Framework 3.5 and 4.8.1 Cumulative Update for Windows 11 25H2 and Server 24H2 — navanem Microsoft KB cover
KB5087051 · .NET · .NET Update

Summary

This is a security-focused cumulative update for .NET Framework 3.5 and 4.8.1, targeting Windows 11, version 25H2 and Microsoft server operating system 24H2. Released on May 12, 2026, it addresses two Elevation of Privilege vulnerabilities and includes cumulative reliability improvements. Microsoft recommends applying it as part of regular maintenance. Source: Microsoft Support

Improvements and fixes

  • Patches a .NET Framework Elevation of Privilege vulnerability identified as CVE-2026-32177.
  • Patches a second .NET Framework Elevation of Privilege vulnerability identified as CVE-2026-35433.
  • No new quality or reliability improvements are included in this update beyond the security fixes noted above.

Known issues

Microsoft lists no known issues for this update at the time of writing.

How to get this update

This update is available through multiple servicing channels. No special manual action is required for most environments, though WSUS administrators must confirm the correct product and classification configuration.

  • Windows Update and Microsoft Update - The update downloads and installs automatically. No additional steps are needed.
  • Windows Update for Business - Also delivered automatically with no additional steps required.
  • Microsoft Update Catalog - A standalone package can be downloaded directly from the Microsoft Update Catalog website for manual or offline deployment.
  • Windows Server Update Services (WSUS) - The update syncs automatically when WSUS is configured with Product set to "Windows 11, version 25H2 and Microsoft server operating system 24H2" and Classification set to "Security Updates".

Prerequisites: .NET Framework 3.5 or 4.8.1 must already be installed on the target system before applying this update.

Restart requirement: A system restart is required after applying the update if any of the affected files are in use at the time of installation. Microsoft recommends closing all .NET Framework-based applications before beginning the installation.

Frequently asked questions

Does this update apply to both Windows 11 and Windows Server?

Yes. KB5087051 applies to Windows 11, version 25H2 and Microsoft server operating system 24H2. Both platforms share the same update package because they run on the same underlying .NET Framework 3.5 and 4.8.1 components targeted by these security fixes.

What vulnerabilities does this update address?

The update addresses two Elevation of Privilege vulnerabilities in .NET Framework: CVE-2026-32177 and CVE-2026-35433. Both are classified as Elevation of Privilege issues. No quality or reliability changes are bundled alongside the security fixes in this release.

Will this update install automatically, or do sysadmins need to take action?

For most environments using Windows Update, Microsoft Update, or Windows Update for Business, the update installs automatically with no manual steps. WSUS administrators need to verify that the correct product and classification settings are configured so the update syncs properly to managed endpoints.

Is a restart always required after installing this update?

A restart is required only if files affected by the update are in active use during installation. To reduce the chance of a forced restart, Microsoft recommends that administrators close all .NET Framework-based applications before applying the update in managed deployment scenarios.

#dotnet#security-update#elevation-of-privilege#windows-11-25h2#server-24h2#cumulative-update

Related topics